Pick a case type and the platforms in scope. Get a prioritized artifact collection checklist with file and registry paths, what each artifact proves, MITRE ATT&CK mapping and free or open-source tools to parse it. It works with any forensic suite.
Select a case type above to generate
your investigation artifact checklist.