01Comprehensive artifact reference for Windows execution and Linux persistence locations
02Pre-configured LCQL patterns for process, network, and file activity timelines
03Deep-dive memory analysis including mapping, string extraction, and handle listing
04Dynamic epoch timestamp calculation for precise relative time queries
05Six-phase forensic methodology covering identification through reporting
060 GitHub stars