Windows Event Logs can be daunting especially if it's a lot. No one can actually sit in front of their computer to check each of those logs one by one thru a manual approach. Here are some of the newest EVTX tools that can really save our lives as IR
2\ #Zircolite can be very useful where you can use your favorite sigma rules to detect bad stuff
Dealing with a bunch of memory #forensics lately so I just dump fairly new tools that are useful to all #dfir#incidentresponse out there:
MemProcFS - convenient and easy to use
BulkExtractor - extracts everything into a text file and grep it
SuperMem - CS tool for quick triage
MemProcFS - github.com/ufrisk/MemProc…