$ ps aux

evtx2es, mft2es:

  • Python tools for importing Windows artifacts into Elasticsearch.
  • Included as standard in the DFIR-focused Linux distribution Tsurugi Linux LAB 2022.1 - 2024.1.

ntfsdump, ntfsfind:

  • Forensic tools for extracting Windows artifacts from image files.

Quilter-CSV

  • A tool that provides elastic and rapid filtering for efficient analysis of huge CSV files, such as eventlogs.