Recently asked by a young, aspiring DF/IR practitioner: 'What are some of your current favorite tools?'
My toolkit is large, but here's my current top 10:
1. Sumuri RECON (Mac and iOS forensics) –
@SUMURIForensics
2. Magnet AXIOM (Windows, iOS, and Android forensics) –
@MagnetForensics
3. Cyber Triage (automated DFIR for incident response with artifact scoring) –
@cybertriage
4. X-Ways Forensics (Windows forensics ) –
@XWaysSoftware
5. KAPE (Kroll Artifact Parser and Extractor) –
@EricRZimmerman
6. Digital Detective (NetAnalysis for browser artifacts) –
@DigitalDetectiv
7. Arsenal Recon (advanced disk mounting, hibernation/registry analysis, and evidence exploitation) –
@ArsenalRecon
8. Magnet Verakey (full file system extractions for iOS/Android) –
@MagnetForensics
9. FEX (Forensic Explorer for Windows forensics)
10. Elcomsoft Phone Breaker (iCloud acquisitions) –
@elcomsoft
These all get heavy daily use in my workflow. What's in your toolkit?