Tag Archives: Windows Forensics
TurnedOnTimesView – List PC Running Time Ranges
TurnedOnTimesView is a simple tool that analyses the event log of Windows operating system, and detects the time ranges that your computer was turned on.
TAC – Timeline ActivitiesCache Parser
Microsoft released a Windows 10 update with the capability to show a chronology of actions taken by the user. This new application is called Timeline and is part of Windows Task View. TAC - Timeline ActivitiesCache Parser allows user to
Rifiuti2 – Windows Recycle Bin Analysis Tool
Rifiuti2 analyse recycle bin files from Windows. Analysis of Windows recycle bin is usually carried out during Windows computer forensics.
AlternateStreamView – Tool to Investigate ADS File System
AlternateStreamView is a small utility that allows you to scan your NTFS drive, and find all hidden alternate streams stored in the file system.
CurrProcess – Tool to Display Currently Running Processes
CurrProcess utility is another nirsoft product that you can use among your toolkit for incident response.