Timeline Reconstruction Prompt
Prompt
Build chronological incident timeline from logs. Normalize timestamps, identify first malicious action, map lateral movement.
Why it works
Timestamp normalization prevents timeline errors; evidence tagging maintains forensic integrity.
Watch out for
Log gaps create inferred events; mark confidence. Timezone conversion errors distort timeline.
Used by
IT & Ops Teams