Digital forensics Institution-led
ADTimeline
PowerShell utility that reconstructs partial timelines of Active Directory object changes from replication metadata for incident investigation and threat hunting.
By ANSSI · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- ANSSI
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- GPL-3.0
- Upstream status
- Maintenance unconfirmed
- Evidence class
- Institution-led
What the sources establish
Origin notePublished by ANSSI with French agency presentations of the method in 2019.
Reported capabilities
- Builds partial timelines of selected Active Directory objects and attribute changes.
- Includes a Splunk app with dashboards for suspicious directory changes.
- Highlights group, ACL and privileged-account changes for analyst triage.
Scope and limits
Replication metadata yields only a partial timeline; suspicious-change dashboards require analyst review. No recent upstream release or support guarantee was verified.
Inspect the research evidence 3 source observations
identity / capabilities / deployment / license
README describes the PowerShell timeline script, partial AD replication metadata history, suspicious-activity Splunk dashboards and GPL-3.0 licensing.
Read sourceorigin / country
ANSSI profile identifies this organization as a home for agency-developed projects.
Read sourcemaintenance
The repository documents historical 2019 presentations but no recent release or explicit current maintenance commitment was verified.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow