01Windows artifact parsing including Prefetch, ShimCache, and Amcache
02Forensic disk imaging and evidence integrity verification
034,121 GitHub stars
04Volatile data and memory acquisition workflows using Volatility 3
05Timeline reconstruction and super-timeline generation with Plaso
06Structured reporting for initial access and persistence mechanism analysis