DFIR Toolkit: CLI tools for forensic investigation of Windows artifacts

DFIR Toolkit CLI tools for forensic investigation of Windows artifacts Overview of timelining tools   Install cargo install dfir-toolkit Tool cleanhive merges logfiles into a hive file xx evtx2bodyfile Example   evtxanalyze Analyze evtx...