← Back to catalog
Sysinternals
by Tool host OS / runtime environment
Sysinternals by Tool host OS / runtime environment. A digital forensics tool for forensic tool suite (windows investigations).
Platforms
Windows
Artifact types
Event Logs (EVTX)File SystemPrefetch FilesWindows Registry
License
Open SourceSkill level
IntermediateVersion
v1Website
http://www.microsoft.comUse cases
incident response
Techniques
artifact parsingpost mortem