Small tools, disciplined use

Analyst Utilities

Use trusted system and productivity utilities to inspect, hash, unpack, document, and manage evidence without losing investigative context.

2utility routes8practical tools1recorded purpose
01

Use utilities deliberately

A familiar tool can still alter evidence or create ambiguity if its purpose is not recorded.

Stage 1Define the immediate purpose

State the task the utility must perform and the evidence or working copy it will touch.

Ask: What question or workflow need does this tool address?
02

Choose a utility path

Use focused system utilities for live inspection and general utilities for evidence-handling support.

Best matchStart with Sysinternals Suite

Use focused Microsoft utilities to inspect Windows processes, persistence, files, and system activity.

03

Build your foundation

Understand each utility family and its effect on evidence before using it.

04

Choose a tool by task

Start with the smallest utility that meets the immediate need.

Best starting point for Windows system inspectionSysinternals Suite

Use Microsoft's focused utilities to inspect processes, persistence, file access, networking, and system details.

Also consider A dedicated forensic artefact tool when working from an acquired image.
Explore Sysinternals Suite
05

Check utility readiness

Confirm provenance, purpose, and evidence protection before running a tool.

!
Preparation required5 checks remaining.