Advancing cyber incident timeline analysis through retrieval-augmented generation and large language models

Cyber timeline analysis or forensic timeline analysis is critical in digital forensics and incident response (DFIR) investigations. It involves examining artefacts and events---particularly their timestamps and associated metadata---to detect anomalies, establish correlations, and reconstruct a deta...

Full description

Bibliographic Details
Main Authors: Loumachi, Fatma Yasmine, Ghanem, Mohamed Chahine, Ferrag, Mohamed Amine
Format: Article
Language:English
Published: MDPI 2025
Subjects:
Online Access:https://repository.londonmet.ac.uk/10080/7/computers-14-00067.pdf