Portable forensic acquisition toolkit — Disk imaging, RAM capture, write bloc…
Forensic analysis workstation — NTFS browser, file carving, timeline, keyword…