Building a Network Timeline from TCP, DNS, HTTP, and TLS Connections

A Network Timeline is built by mapping flow, times, protocols, DNS/TLS/HTTP, and asset context. A single packet or connection is partial evidence, so a sequence is built and verified against additional sources.
Network traffic provides a perspective that does not solely depend on the endpoint. It allows identifying who communicated with whom, using which protocol, in what order, and at what volume, but requires an understanding of visibility limits and encryption. This article focuses on Network Timeline and is intended for SOC analysts and network investigators. The goal is to provide a working methodology that can be applied in practice, during professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always incomplete. Query name, response code, TTL can indicate a direction, but their meaning depends on the time, asset, user, and expected activity. Therefore, we will build the examination around an investigative question, required evidence, and clear completion criteria.
The practical scenario in the article is: a timeline of a Download followed by Beaconing. All examples are lab data or process descriptions. When dealing with Penetration Testing, Web, or Cloud, work only with explicit authorization, defined scope, and the ability to stop the test.




