dfir-gui-tools.md (24127B)
1 --- 2 title: "DFIR GUI Tools" 3 description: "Click-path walkthroughs for the point-and-click half of DFIR: Autopsy (case, data source, ingest modules, results tree, keyword lists, timeline, report), FTK Imager, Arsenal Image Mounter, Registry Explorer, Timeline Explorer, ShellBags Explorer, Event Log Explorer and Hayabusa HTML, plus Velociraptor and Timesketch for team review." 4 category: dfir 5 subcategory: "Analysis" 6 tags: [dfir, forensics, gui, autopsy, sleuth-kit, ftk-imager, registry-explorer, timeline-explorer, shellbags, event-logs, windows, linux] 7 tools: ["Autopsy", "FTK Imager", "Arsenal Image Mounter", "Registry Explorer", "Timeline Explorer", "ShellBags Explorer", "MFTExplorer", "EZViewer", "Event Log Explorer", "Hayabusa", "Velociraptor", "Timesketch", "Wireshark", "HxD / ImHex"] 8 difficulty: intermediate 9 updated: "2026-09-26" 10 --- 11 12 # DFIR GUI Tools 13 14 The command-line parsers in [EZ Tools](/sheets/dfir/ez-tools-kape) and [Linux forensics](/sheets/dfir/linux-forensics) produce the data; these tools are where you **read** it, browse an image like a filesystem, and build the picture you put in the report. Each section below is a **click path**: what to open, in what order, what each pane is telling you, and the two or three features people miss for years. Autopsy gets the most room because it is the free, cross-platform full suite most modules teach; the Zimmerman GUIs get the second most because they are what you will use daily on Windows cases. 15 16 > [!info] GUI ≠ point-and-hope 17 > Every GUI here is a viewer over the same artefacts the CLI tools parse. Know **which artefact** a result node came from (Autopsy tells you in the *Source File* column; Registry Explorer in the key path) so you can cite it, reproduce it on the command line, and explain its caveats. A finding you cannot explain is not a finding. 18 19 ## Autopsy 20 21 Open-source (Basis Technology / Sleuth Kit), Windows installer or Linux/macOS via the zip + `unix_setup.sh`. It ingests raw/E01/VHD/VMDK images, local disks, logical folders, and *unallocated-space* files, runs **ingest modules** in the background, and files everything into a **results tree**. Version 4.2x; Java is bundled on Windows. 22 23 ### Case → data source → ingest 24 25 1. **New Case** → name, base directory (put it on fast local disk, not the evidence drive), single-user. Fill *Examiner* and *Case number* — they land in the report. 26 2. **Add Data Source** → *Disk Image or VM File* (E01, dd, VHD, VMDK, split images pick `.001`/`.E01` only) → set **Time zone of the source machine** (critical: Autopsy displays in *its* configured zone; set both under Tools → Options → View) → *Ignore orphan files in FAT* only if you are in a hurry → **Next**. 27 - Other types: *Local Disk* (needs admin; use a write blocker), *Logical Files* (a KAPE/UAC triage folder — Autopsy will still run keyword/hash/recent-activity modules over it), *Unallocated Space Image File* (the `blkls` output), *Autopsy Logical Imager Results*. 28 3. **Configure Ingest** — tick modules. First pass, keep it lean so results appear fast: 29 30 | Module | Does | Tick on first pass? | 31 |---|---|---| 32 | **Recent Activity** | registry (via RegRipper), browser history/downloads/cookies, Recycle Bin, USB, installed programs, shellbags, recent docs, OS info | yes — the Windows overview | 33 | **Hash Lookup** | MD5 every file, compare to NSRL (known-good) and your notable sets | yes, once you have imported an NSRL/notable hash set under Tools → Options → Hash Sets | 34 | **File Type Identification** | libmagic every file (needed by many others) | yes | 35 | **Extension Mismatch Detector** | `.jpg` that is really an exe | yes | 36 | **Embedded File Extractor** | opens ZIP/RAR/7z/DOCX/PDF and ingests contents as child files | yes (slow on big images) | 37 | **Picture Analyzer** | EXIF/GPS from images | yes | 38 | **Keyword Search** | indexes text (Solr) and runs lists: emails, IPs, URLs, phone, credit cards, your custom regexes | yes with only the lists you need; the **index** step is what makes the case slow | 39 | **Email Parser** | PST/mbox/EML → messages, attachments | if mail matters | 40 | **Encryption Detection** | high-entropy files, password-protected Office/PDF/zips | yes | 41 | **Interesting Files Identifier** | rule sets: files/dirs by name, path, size (ship: cloud storage, crypto wallets, VPN clients, anti-forensics tools) | yes | 42 | **Central Repository** | correlates hashes/emails/USB IDs across all your cases | yes in a multi-case shop | 43 | **PhotoRec Carver** | carves unallocated space with PhotoRec | second pass — slow, noisy | 44 | **Virtual Machine Extractor** | finds `.vmdk`/`.vhd` inside the image and ingests them as data sources | if present | 45 | **Data Source Integrity** | verifies E01 hash | yes | 46 | **Plaso** | runs log2timeline over the source for the Timeline view | second pass — very slow; usually run plaso yourself | 47 | **Android Analyzer / iOS (aLEAPP/iLEAPP)** | mobile extractions | mobile only | 48 | **YARA Analyzer** | your rule sets over every file | yes with a case rule set | 49 | **Drone Analyzer, Cyber Triage Malware Scanner** | niche / paid | no | 50 51 4. **Finish**. Ingest runs in the background (progress bar bottom right); results appear in the tree as modules finish. You can browse immediately — file system nodes are available the moment the image is parsed. 52 53 > [!tip] Ingest order that saves an afternoon 54 > Run *Recent Activity + File Type + Hash Lookup + Extension Mismatch + Interesting Files + Encryption Detection* first (30–90 min for a 500 GB image). Read those results while a **second ingest** (right-click the data source → *Run Ingest Modules*) does Keyword Search indexing, Embedded File Extractor and, if you must, PhotoRec. 55 56 ### Reading the tree (left pane) 57 58 | Node | What is in it | 59 |---|---| 60 | **Data Sources** → image → volumes | the filesystem as-is; `$OrphanFiles`, `$Unalloc`, `$CarvedFiles` are synthetic dirs Autopsy adds. Deleted files show with a red **X** icon and are browsable | 61 | **File Views → File Types → By Extension / By MIME Type** | all images, all documents, all executables regardless of where they are — start here for "any PowerShell scripts on this box?" | 62 | **File Views → Deleted Files** | *File System* (metadata still present — timestamps intact) vs *All* (incl. carved) | 63 | **File Views → File Size** | 200 MB+ files: containers, archives, VMs, dumps | 64 | **Data Artifacts** (older versions: Extracted Content) | **Installed Programs, Operating System Information, OS Accounts, Recent Documents, Run Programs, Shell Bags, USB Device Attached, Web Bookmarks/Cookies/Downloads/History/Search/Form Autofill/Account Type, Recycle Bin, Metadata, EXIF, Email Messages, Encryption Detected/Suspected, Extension Mismatch, Interesting Items, Keyword Hits, Hashset Hits, YARA Hits** | 65 | **Analysis Results** (4.19+) | scored results: **Interesting Items, Keyword Hits, Hashset Hits, Encryption, Extension Mismatch, YARA, Web Categories, Previously Seen/Notable/Unseen** (central repo) | 66 | **OS Accounts** | every account with SID, home, login count, last login (from SAM + registry) — click one → *OS Account* tab lists everything attributed to it | 67 | **Tags** | your bookmarks, by tag name | 68 | **Reports** | generated reports | 69 70 Right pane tabs for any selected file: **Hex, Text (strings / indexed text / translation), Application (image/PDF/HTML/SQLite/registry/PList viewer), File Metadata (all TSK times, MD5, MIME, `$MFT` entry, sectors), OS Account, Data Artifacts, Analysis Results, Context (where it came from: download URL, email attachment, zip parent), Annotations (your comments/tags), Other Occurrences (central repo: seen in another case?)**. 71 72 ### The moves that matter 73 74 ```text 75 Right-click any file → Tag File → Bookmark / Follow Up / Notable Item (tags are what you report) 76 → Extract File(s) (with original name; keep timestamps via Tools → Options → General) 77 → View in Directory / View Source File / View in Timeline 78 → Add File to Hash Set (build your notable set as you go) 79 → Search for files with the same MD5 80 Right-click a directory → Extract (whole tree) 81 Data Source right-click → Run Ingest Modules (second pass) / Add Data Source Hash / Delete 82 Tools → File Search by Attributes name / size / MIME / date range / known status / hash — "all files modified 20–22 Sep under Users\" 83 Tools → Run Ingest Modules / View Ingest Progress / Ingest Inbox (alerts as hits land) 84 Keyword Search (top right bar) exact / substring / regex, over the Solr index — ad hoc, after indexing finished 85 Tools → Options → Keyword Search → Lists add a case list: attacker tool names, IPs, hostnames, user names, "mimikatz|rubeus|sharphound|rclone|anydesk" 86 Tools → Options → Interesting Files import the community rules (github.com/sleuthkit/autopsy/... or your own XML) — flags cloud sync, VPN, TOR, wipers by name 87 Tools → Options → Hash Sets import NSRL (known), notable sets (yours / ClamAV / community); Central Repository → import from case 88 Tools → Timeline see below 89 Tools → Image/Video Gallery thumbnail wall grouped by folder, with EXIF/GPS; tag from there 90 Tools → Communications graph + table of accounts (email, phone, IM) and who talked to whom 91 Tools → Geolocation every GPS point from EXIF/browser/mobile on a map, KML export 92 Discovery (toolbar) images / videos / documents / domains by size, date, "past occurrences" — fast triage of media and web activity 93 Tools → Generate Report HTML / Excel / KML / STIX / Portable Case (a mini-case with just the tagged items you can hand to counsel) 94 ``` 95 96 ### Timeline view 97 98 **Tools → Timeline** opens a separate window with two modes. **Counts** (bar chart per time unit — spot the spike of activity at 03:00) → drag to zoom → switch to **Details** (event clusters by path, expand to individual events) or **List** (a table you can sort/filter/export). The **Filters** pane on the left: hide known files, text filter on path, event types (File System: M/A/C/B; Web; Misc: recent docs, installed programs, USB, exif, log entries...). Right-click an event → *View File in Directory*. Everything you **tag** shows as a pin. It draws from TSK timestamps plus the Recent Activity results; if you ran the Plaso ingest module the log events appear too. 99 100 ### Autopsy vs Sleuth Kit CLI 101 102 Autopsy **is** Sleuth Kit with a Java GUI and a results database (`autopsy.db`, SQLite — open it with `sqlite3` when you want a bulk export the GUI does not offer: `tsk_files`, `blackboard_artifacts`, `blackboard_attributes`). Anything Autopsy shows, [`fls`/`icat`/`istat`](/sheets/dfir/linux-forensics#sleuth-kit-essentials) can reproduce for the report appendix. 103 104 > [!warning] Autopsy limits 105 > Single-user cases lock the `.aut` — one analyst at a time (multi-user needs PostgreSQL + Solr + ActiveMQ). Keyword indexing of a full disk can take a day; scope it. Autopsy parses registry via RegRipper and shellbags/browser history natively, but for **serious Windows artefact work** (MFT with `$FN` timestamps, USN, Prefetch run times, Amcache SHA-1, SRUM, ShimCache) export the files and use the EZ Tools. Its browser parsing lags Chrome/Firefox schema changes — cross-check with `SQLECmd`/hindsight. 106 107 ## FTK Imager 108 109 Exterro (formerly AccessData), free. Imaging is in [acquisition](/sheets/dfir/disk-imaging#ftk-imager-windows-gui--cli); this is the **viewer** side. 110 111 - **File → Add Evidence Item** → Image File (E01/dd/AD1/AFF), Physical Drive, Logical Drive, or Contents of a Folder. Evidence Tree (top-left) → File List (top-right, with dates/size/type) → **Hex + Properties/Hex Value Interpreter/Custom Content** (bottom). 112 - Every NTFS metafile is browsable: `[root]\$MFT`, `$LogFile`, `$Extend\$UsnJrnl:$J`, `$Secure`, `$Recycle.Bin`, plus `[unallocated space]` and `[orphan]`. Right-click → **Export Files** (keeps original timestamps, writes an export log with hashes) → this is how you hand `$MFT` and the hives to MFTECmd/Registry Explorer without mounting anything. 113 - **Alternate Data Streams** show as child entries of the file (`file.exe:Zone.Identifier`). Deleted files show with a red **X** and are exportable if their clusters survive. 114 - **Properties** tab: all four timestamps, `$MFT` record number, allocated/unallocated, start cluster. **Hex Value Interpreter**: select bytes → see them as DOS date, FILETIME, Unix time, int — decoding a raw timestamp without a calculator. 115 - **File → Obtain Protected Files** (on a live system): grabs `SAM`, `SECURITY`, `SOFTWARE`, `SYSTEM`, `NTUSER.DAT`s, `$MFT` — locked files nothing else copies. 116 - **File → Image Mounting**: mount an image as a drive letter (Physical & Logical, **Block Device / Read Only**) so KAPE, EZ Tools or AV can run against it; **File → Unmount** when done. 117 - **File → Export File Hash List**, **Export Directory Listing** (CSV of every file with timestamps: the poor man's `fls`). 118 - **Custom Content Image**: right-click any files/dirs → *Add to Custom Content Image (AD1)* → File → Create Custom Content Image — a hashed, forensically-wrapped export of just those items (what a triage collection looked like before KAPE). 119 120 ## Arsenal Image Mounter 121 122 Free (the paid tier adds write-temporary and VSS-delete). Mounts **E01/raw/VHD/VMDK/AFF4** as a **real SCSI disk** at the Windows disk layer, so Volume Shadow Copies, BitLocker (if you have the key/password), Storage Spaces and dynamic disks behave — things FTK Imager's mounter does not do. **Mount disk image → pick file → Read only** (or *Write temporary* to let Windows "fix" a dirty NTFS volume in a scratch file without touching the image) → OK. The mounted disk appears in Disk Management; volumes get letters. Then: `vssadmin list shadows /for=F:` and `mklink /d C:\vss1 \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\` to browse a shadow copy, or point KAPE `--tsource F: --vss`. Also **launches a Windows VM from the image** (Hyper-V/VirtualBox) — booting the suspect's OS for a screenshot of their desktop, with the image untouched. 123 124 ## Registry Explorer (Eric Zimmerman) 125 126 The registry GUI; `RECmd` is its CLI twin ([own sheet](/sheets/dfir/recmd)). 127 128 - **File → Load hive** → pick `SYSTEM`/`SOFTWARE`/`SAM`/`SECURITY`/`NTUSER.DAT`/`UsrClass.dat`/`Amcache.hve`. If `.LOG1/.LOG2` sit next to it you are asked to **replay transaction logs** — say yes; it writes a clean copy (`*_clean`) and shows what changed. A hive loaded without its logs can be missing the last minutes/hours of writes. Load several hives at once (multi-select). 129 - **Left tree** = keys with last-write time. **Right grid** = values (name, type, data, raw). Bottom: **Type Viewer** (decoded data: FILETIME, ROT13 UserAssist, binary structures), **Slack Viewer**, **Hex**. 130 - **Bookmarks tab** (right of the tree): hundreds of pre-defined "keys of interest" grouped by hive — *Common* (Run keys, services, USBSTOR, MountedDevices, NetworkList, TimeZone, ProfileList, Uninstall...) and *User created*. Click one → jump. Bookmarked keys show **red** in the tree, **blue** = has a plugin. 131 - **Plugins**: keys with a decoder get an extra grid tab — **UserAssist** (decoded names, run counts, focus time), **ShellBags** (in-place), **USBSTOR**, **MountedDevices**, **NetworkList**, **TypedURLs**, **WordWheelQuery**, **RecentDocs**, **OpenSavePidlMRU**, **SAM** (users, RIDs, last login, password set, login count, groups), **Services**, **AppCompatCache**, **BAM**, **TaskCache**, **Amcache**, **TerminalServerClient**, **7-Zip/WinRAR history**, **WinSCP/Putty sessions** ... Right-click a plugin grid → *Export* CSV/XLSX. 132 - **Deleted keys/values**: `Options → Recover deleted keys/values` (default on) puts a **`Unassociated deleted records`** node and marks recovered items — this is what you show when the attacker cleaned a Run key. 133 - **Search**: `Ctrl+F` / **Tools → Find** — key names, value names, value data (string/hex), **date range on last-write**, regex; results grid, double-click to jump. "All Run-key-like values with `.exe` under `AppData` in the last 30 days" is one search. 134 - **Timestamps**: right-click a key → *Export → Key and subkey last write times* for the timeline; the whole hive → *File → Export → Hive to CSV* is what `RECmd --csv` does. 135 - **Project**: File → Project → Save keeps loaded hives + bookmarks + expanded state. 136 137 ## Timeline Explorer (Eric Zimmerman) 138 139 Covered from the CSV side in [EZ Tools](/sheets/dfir/ez-tools-kape#timeline-explorer--reviewing-the-csvs). The habits that make it fast: 140 141 - **File → Open** several CSVs at once (or drag a folder) → one tab each; **File → Session → Save** so tomorrow you reopen the whole case with filters and tags. 142 - **Filter row** under the header for every column: `%rclone%` (contains), `2026-09-2%` (dates as text), `>2026-09-20 03:00`, `= 4624`, `Like`, `In (4624,4625)`. Click the funnel on a header for the pick-list. **Filter editor** (bottom-left funnel) for boolean chains across columns; the current filter is shown as text at the bottom — copy it into your notes. 143 - **Ctrl+F**: search all columns; **Ctrl+T** toggles tag on selected rows; **Tag** column checkboxes; **Tools → Show only tagged / Clear tags**. 144 - **Group by** by dragging a column header into the group band: `EventId` for evtx, `ParentPath` for MFT, `ExecutableName` for Prefetch. Collapse everything, expand the interesting groups. 145 - **Conditional Formatting** (right-click header) → *Highlight Cell Rules* — colour 4624 green, 4625 red, 4672 yellow, 7045 orange, 1102 purple; save as part of the layout. 146 - **Column Chooser** (right-click header) to hide the 60 columns you do not need; **Best Fit (all columns)** after. 147 - **Line/Tag/Wrap**: View → *Word wrap* for `Payload`; **View → Show/hide detail pane**. 148 - **Copy**: `Ctrl+C` copies selected rows with headers; **File → Export** the filtered/tagged view to XLSX/CSV/HTML → the appendix. 149 - Timeline Explorer opens **any** CSV/TSV (plaso `psort -o l2tcsv`, Hayabusa CSV, `mactime -d` output). Dates are recognised if they parse; set `--dt` in the EZ tools to ISO if a locale fights you. 150 151 ## ShellBags Explorer (Eric Zimmerman) 152 153 **File → Load offline hive** → pick `UsrClass.dat` (Win7+ Explorer bags live here), then it offers to load the matching `NTUSER.DAT`; or **File → Load active registry** on a live box. Left: the **folder tree as the user saw it** — This PC, drives, `\\server\share`, removable, Control Panel, zip files browsed as folders. Click a node → grid of children with **First Interacted / Last Interacted**, **MFT entry/sequence** (pivot to MFTECmd output), **Absolute path**, **Shell type** (GUID-based, network, file entry, zip content...). Pink = has children; italics = derived. **Search** box filters the tree. **Export → CSV** of everything = what `SBECmd` produces. Read the `Value` column: bag numbers give the order the user created them. 154 155 ## MFTExplorer and EZViewer 156 157 **MFTExplorer**: File → Load `$MFT` → tree of the volume on the left, and for the selected record the full parsed `$STANDARD_INFORMATION` / `$FILE_NAME` / `$DATA` attributes (all timestamps side by side, resident data in hex, data runs, ADS, security id). It is slow on big MFTs (minutes) but is how you *show* a timestomp in a screenshot. **EZViewer**: drag any file onto it — images, Office, PDF, text, hex — renders without the real application ever touching the evidence; the default double-click target for a forensic workstation. 158 159 ## Event logs: Event Viewer, Event Log Explorer, Hayabusa HTML 160 161 - **Windows Event Viewer**: *Action → Open Saved Log* on an exported `.evtx`; *Filter Current Log* by ID, level, time; **XML view** of an event for the fields; *Create Custom View* across channels. Usable, slow, no cross-log timeline — export to EvtxECmd for anything real. 162 - **Event Log Explorer** (FSPro, free for personal use): opens dozens of `.evtx` at once, merges them into one view, filters by ID/user/text with saved filter sets, and follows `Description` fields to columns. The best pure-GUI evtx reader on Windows. 163 - **Hayabusa** (`hayabusa.exe csv-timeline -d Logs -o out.csv` or `html-report`): Sigma-rule detection; the **HTML report** (`-H report.html`) gives rule hits by severity, a timeline chart, top computers/users — the executive view before you dive into Timeline Explorer on the CSV. **Chainsaw** (`chainsaw hunt Logs/ -s sigma/ --mapping mappings/sigma-event-logs-all.yml -r rules/ --csv --output out/`) is the alternative, also with an ASCII table output. 164 - Linux: `journalctl` has no GUI worth using; `gnome-logs` for live boxes, otherwise plaso → Timesketch. 165 166 ## Wireshark 167 168 The pcap GUI; the CLI lives in [TShark](/sheets/dfir/tshark). Habits for DFIR: **Statistics → Conversations / Endpoints / Protocol Hierarchy** first (who talked to whom, how much), **Statistics → HTTP → Requests**, **File → Export Objects → HTTP/SMB/TFTP/DICOM** to pull transferred files, **Follow → TCP/TLS stream**, **Analyze → Decode As** for odd ports, colouring rules, and `frame.time >= "2026-09-20 03:00:00"` as a display filter. Add columns by right-click on a field → *Apply as Column* (`http.host`, `tls.handshake.extensions_server_name`, `dns.qry.name`). **Edit → Preferences → Protocols → TLS → (Pre)-Master-Secret log filename** decrypts TLS when you captured `SSLKEYLOGFILE` from the endpoint. 169 170 ## Team-scale review: Velociraptor and Timesketch 171 172 - **Velociraptor** (Rapid7, free): a web GUI server + agents; the *Artifacts* are VQL queries for every Windows/Linux/macOS artefact (`Windows.KapeFiles.Targets` runs KAPE targets remotely, `Windows.EventLogs.Hayabusa`, `Linux.Sys.*`, `Generic.Forensic.Timeline`). **Hunts** run an artifact across the fleet and return one table; **Notebooks** let you query results with VQL; **Offline Collector** builds a standalone triage `.exe` for boxes without an agent. When you have more than a handful of hosts, this replaces walking around with KAPE. 173 - **Timesketch** (Google, free, Docker): upload plaso `.plaso` files or CSV/JSONL timelines → a web timeline multiple analysts search (`data_type:"windows:evtx:record" AND event_identifier:4624`), tag, star, comment and build **stories** on. Sigma rules can be run over it; **Timesketch + plaso** is the Linux-side answer to Timeline Explorer for a whole team. `psort.py -o timesketch` or the web upload feeds it. 174 175 ## Which GUI for which job 176 177 | Job | Tool | 178 |---|---| 179 | Browse an image, export files, look at deleted ones, run keyword/hash/YARA over everything | **Autopsy** (or FTK Imager for browse/export only) | 180 | Get `$MFT`, hives, `$J` out of an image or a live box without mounting | **FTK Imager** | 181 | Mount an image so KAPE / AV / EZ Tools see a drive letter (with VSS) | **Arsenal Image Mounter** | 182 | Read/parse registry with decoded plugins, deleted keys, transaction logs | **Registry Explorer** | 183 | Review any parser CSV, filter, tag, colour, export the report table | **Timeline Explorer** | 184 | Folders a user browsed | **ShellBags Explorer** | 185 | Show a timestomp or resident data in a screenshot | **MFTExplorer** | 186 | Open an evidence file safely | **EZViewer** | 187 | Read many event logs as one, quick | **Event Log Explorer** / **Hayabusa HTML** | 188 | Pcap | **Wireshark** | 189 | Media wall, faces, GPS | **Autopsy Image Gallery / Geolocation** | 190 | Many hosts, one console | **Velociraptor** | 191 | Team timeline review | **Timesketch** | 192 | Hex + structure decoding | **ImHex** / **HxD** / **010 Editor** | 193 194 ## Related 195 196 - [EZ Tools & KAPE](/sheets/dfir/ez-tools-kape) — the CLI parsers behind Registry/Timeline/ShellBags Explorer 197 - [RECmd](/sheets/dfir/recmd) — Registry Explorer's command-line twin 198 - [Acquisition](/sheets/dfir/disk-imaging) — FTK Imager / Guymager imaging, mounting 199 - [Linux forensics](/sheets/dfir/linux-forensics) — Sleuth Kit CLI that Autopsy wraps, plaso for Timesketch 200 - [TShark](/sheets/dfir/tshark) — Wireshark's CLI