It depends if I analyze disk or memory.
In case of memory I use most volatility and some some own scripts which do carving with respect to memory.
In case of disks I use Encase and enscripts
. Of course SleuthKit, DFF and lot of more. It actually very depends on tasks needed to complete. In lot of cases Encase is enough.