Learn about the importance of having a timeline overview of events that took place on the mobile device and how to drill down into a specific moment in time as it relates to a real-world event. 

Digital Forensics Specialist Matt Fullerton
Digital Forensics Specialist

Have you ever wondered how much user-generated activity you can find on a mobile device in one week? If you look at the granular detail, it could very quickly be overwhelming to parse and analyze all the different artifacts found in that timeframe. You could be subjecting yourself to THOUSANDS of artifact entries. What if I told you that a tool exists that could parse out all the relevant artifacts needed for your case and make them easy to view in a chronological timeline?

Dive Into Actionable Intelligence with the ArtifactIQ by Grayshift Timeline

Enter ArtifactIQ by Grayshift. The timeline feature is one of the strongest capabilities of ArtifactIQ, and it’s user-friendly for even the least technically savvy person. With the ability to view all the artifacts in the select ArtifactIQ categories or zoom in and go as granular as minute-by-minute, the timeline will provide you with a quick, succinct overview of information on the device.

Have a custom date range you need to focus on? Easy! Want to see how many clues are in view? Easy! Look at the “clues in range” indicator, along with a scrollable list of what you might find. Gone are the days of needing to “build” a timeline, as seen in other forensic analysis tools. ArtifactIQ by Grayshift does this for you automatically, so you can dive right in and start finding that actionable intelligence imperative to your case.

How to Use the ArtifactIQ by Grayshift Timeline

Let’s put this into perspective with a real-life scenario: say you are investigating a cold-reported crime that occurred one week before the date you were able to acquire the data from a vital device. As mentioned above, that one-week post-incident could contain thousands of unrelated artifacts. Using the ArtifactIQ by Grayshift timeline feature, you can easily navigate to and isolate those artifacts that are important to you and your case.

Want to know what happened in a granular, five-minute window? Easy! Enter your custom date range in the dialog box or use your mouse scroller wheel to drill down exactly what clues are essential to you.

Want to cross-reference the clues located in the timeline? Easy! Click on a clue, and it will take you to where it is in the other categories supported in ArtifactIQ by Grayshift. From there, you can keep it on the surface and view the most important facts about the clue – creation dates, modified dates, file name, and any metadata.

Want to dig a little deeper? Easy! Expand the carrots within the clue and see all the super technical nerd data that will help you not only identify the clue but verify and validate with its direct file path derivation.

Are you starting to see a trend here? We designed ArtifactIQ by Grayshift to be easy to navigate, use, and understand while still fulfilling those technical details that are needed to set your case up for success. The ArtifactIQ by Grayshift timeline feature is a straightforward function that can help you analyze the data quickly and have an even quicker turnaround time on your analysis.

