Digital forensics Institution-led

ADTimeline

PowerShell utility that reconstructs partial timelines of Active Directory object changes from replication metadata for incident investigation and threat hunting.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Maintenance unconfirmed
Evidence class
Institution-led

What the sources establish

Origin note

Published by ANSSI with French agency presentations of the method in 2019.

Reported capabilities

  • Builds partial timelines of selected Active Directory objects and attribute changes.
  • Includes a Splunk app with dashboards for suspicious directory changes.
  • Highlights group, ACL and privileged-account changes for analyst triage.

Scope and limits

Replication metadata yields only a partial timeline; suspicious-change dashboards require analyst review. No recent upstream release or support guarantee was verified.

Inspect the research evidence 3 source observations
  1. identity / capabilities / deployment / license

    README describes the PowerShell timeline script, partial AD replication metadata history, suspicious-activity Splunk dashboards and GPL-3.0 licensing.

    Read source
  2. origin / country

    ANSSI profile identifies this organization as a home for agency-developed projects.

    Read source
  3. maintenance

    The repository documents historical 2019 presentations but no recent release or explicit current maintenance commitment was verified.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow