wireshark

When doing forensics, the first thing is to copy the drive bit for bit so you can work on the copy.

indicators of compromise (IoC)