Digital Forensics File Timeline Calculator
Analyze file system activity patterns to detect anomalies. Calculates activity rate, deletion ratio, and an anomaly score indicating potential anti-forensic behavior.
About this calculator
Digital forensic examiners look for statistical outliers in file-system activity as a first-pass signal that someone may have tried to cover their tracks. This calculator builds a composite 0-100 anomaly score from three weighted components. The deletion score (worth up to 40 points) scales with the deletion ratio — deleted files as a percentage of everything analyzed — on the reasoning that mass deletion is a classic anti-forensic move. The suspicious-file score (up to 30 points) scales with what fraction of analyzed files were flagged for anomalous timestamps, hidden attributes, or known wiping-tool signatures.
The activity score (up to 30 points) rewards burst file activity, treating a rate above 100 files/hour as maximally suspicious since legitimate day-to-day use rarely generates that much file churn. The three scores sum to the overall anomaly score, which the calculator then buckets into three plain-language risk tiers: below 40 reads as normal activity, 40-69 as suspicious activity worth a closer look, and 70+ as likely anti-forensic behavior. This is a heuristic triage score, not a forensic conclusion — the scoring weights and thresholds are reasonable defaults, not standards drawn from any particular forensic methodology, and a high score only means the file-system statistics look unusual, not that evidence tampering is proven. Use it to prioritize which systems or time windows deserve deeper manual timeline analysis (MFT parsing, $LogFile review, shadow copy comparison), not as a standalone finding.
Inputs
Results
Anomaly Score
41 / 100
Risk Level
Medium Risk — Suspicious Activity
How to Use This Calculator
- Enter Files Analyzed, Time Range, and Suspicious Files.
- Set Deleted Files.
- Review Anomaly Score (/ 100) and Risk Level.
- Use File Activity Rate (files/hr) and Deletion Ratio (%) to inform your decision.
- Use the chart to visualize the results and explore different scenarios by adjusting inputs.
How the result changes with Files Analyzed
| Files Analyzed | Anomaly Score | Risk Level |
|---|---|---|
| 2,500 | 52 / 100 | Medium Risk — Suspicious Activity |
| 3,750 | 45 / 100 | Medium Risk — Suspicious Activity |
| 7,500 | 37 / 100 | Low Risk — Normal Activity |
| 12,500 | 34 / 100 | Low Risk — Normal Activity |
What each input means
- Files Analyzed
- Total number of files examined in the forensic image.
- Time Range
- Time window of activity being analyzed.
- Suspicious Files
- Files with anomalous timestamps, hidden attributes, or known tool signatures.
- Deleted Files
- Number of deleted or wiped files recovered from unallocated space.
What each result means
- File Activity Rate
- Average files created/modified/deleted per hour.
- Deletion Ratio
- Percentage of analyzed files that were deleted.
- Anomaly Score
- Composite score indicating likelihood of intentional evidence destruction.
- Risk Level
- Classification based on anomaly score thresholds.
How this is calculated
Worked example, using the default values
- Identify Input Parameters4 parametersFiles Analyzed = 5000, Time Range = 24, Suspicious Files = 50, Deleted Files = 200 = 4 input(s) provided
- Calculate Anomaly ScoreAnomaly Score41 = 41
- Calculate File Activity RateFile Activity Rate208.33 = 208.33
- Calculate Deletion RatioDeletion Ratio4 = 4
Engine last updated . Checked against 3 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
How are the three component scores weighted into the final anomaly score?
The deletion score can contribute up to 40 points, scaling as deletionRatio times 2 and capped there; the suspicious-files score can contribute up to 30 points, scaling as the suspicious-to-total ratio times 300 and capped; and the activity score can contribute up to 30 points, scaling with file activity rate and maxing out once the rate reaches 100 files per hour. The three are simply summed for the final 0-100 anomaly score, so deletion activity carries the heaviest single weight of the three factors.
Why does the deletion ratio get compared against total files analyzed rather than a fixed number?
The calculator computes deletionRatio as deleted files divided by files analyzed (times 100), so it's expressed as a percentage of the total dataset rather than a raw count. This makes the metric comparable across investigations of very different scale — 200 deleted files out of 5,000 analyzed (4%) reads very differently than 200 deleted files out of 500 analyzed (40%), even though the raw deletion count is identical.
What file-activity rate triggers the maximum activity score?
The activity score is capped at 30 points and reaches that maximum once fileActivityRate (files analyzed divided by the time range in hours) exceeds 100 files per hour; below that threshold it scales proportionally. The underlying assumption baked into the code is that legitimate day-to-day computer use rarely generates that much sustained file churn, so a rate above 100/hr is treated as maximally suspicious regardless of how much higher it climbs.
Does a high anomaly score prove evidence tampering occurred?
No. The score is a heuristic composite built from three statistical ratios with fixed weights and thresholds chosen as reasonable defaults, not derived from any specific forensic standard or validated dataset. A score of 70+ flags that the file-system statistics look unusual and warrants closer manual review — MFT parsing, $LogFile review, shadow copy comparison — but it is not, by itself, proof that evidence was deliberately destroyed.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Forensic Accounting Calculator
Detect financial discrepancies using the net worth method. Compare reported income against bank deposits, expenses, and asset accumulation.
Forensic ScienceDocument Age Estimation Calculator
Estimate document age from ink volatile analysis and paper acidity. Uses exponential decay modeling of ink solvent evaporation.
Forensic ScienceBlood Spatter Analysis Calculator
Calculate bloodstain impact angle, area of origin, and droplet velocity from stain dimensions. Uses the sine-ratio method for angle determination.
More in Science & Physics.