Effective and Efficient Forensic Analysis via System Monitoring