$ ps aux
evtx2es, mft2es:
- Python tools for importing Windows artifacts into Elasticsearch.
- Included as standard in the DFIR-focused Linux distribution Tsurugi Linux LAB 2022.1 - 2024.1.
ntfsdump, ntfsfind:
- Forensic tools for extracting Windows artifacts from image files.
Quilter-CSV
- A tool that provides elastic and rapid filtering for efficient analysis of huge CSV files, such as eventlogs.