https://www.sans.org/reading-room/whitepapers/forensics/forensic-timeline-analysis-wireshark-giac-gcfa-gold-certification-36137