Traditional timeline analysis can be extremely useful yet it sometimes misses important events that are stored inside files or OS artifacts on the suspect. By solely depending on traditional filesystem timeline the investigator misses context that is necessary to get a complete and accurate...