Hands down. The best combination of #DFIR tools is: Regripper, Regdecoder, Log2timeline, and Sleuthkit.
1
4
4
Replying to @corey_harrell
@corey_harrell You forgot volatility, but otherwise I agree with you.

Sep 30, 2012 · 7:00 PM UTC

1
Replying to @hal_pomeranz
@hal_pomeranz True. Forgot that one since most of the time I don't have a memory image