Tools

This page will serve as a curated list of DFIR related Tools.

ToolDeveloper(s)CategoryDescription
ALEAPPAlexis BrignoniMobile ForensicsAndroid Logs Events And Protobuf Parser.
ALFAInvictus Incident ResponseCloud & SaaSALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework.
Arsenal Image MounterArsenal ReconUtilitiesArsenal Image Mounter mounts the contents of disk images as complete disks in Windows, allowing users to benefit from disk-specific features like integration with Disk Manager, launching virtual machines (and then bypassing Windows authentication and DPAPI), managing BitLocker-protected volumes, mounting Volume Shadow Copies, and more.
BMC-ToolsANSSIDigital ForensicsRDP Bitmap Cache parser.
Aurora Incident ResponseMathias FuchsIncident ResponseIncident Response Documentation made easy. Developed by Incident Responders for Incident Responders.
Belkasoft X CorporateBelkasoftDigital ForensicsProtect your business assets from malware and hacking attempts, perform cyber incident investigations and incident response, comply with legal requirements and regulations in eDiscovery, respond to insider threats, fight cyberharassment and bullying in the workplace.
Belkasoft X ForensicBelkasoftDigital ForensicsBelkasoft X Forensic is the complete solution for conducting in-depth investigations on all types of digital media devices and data sources, including computers, mobile devices, RAM, drones, car images, and the cloud.
Belkasoft Remote AcquisitionBelkasoftData AcquisitionDigital forensic and incident response tool developed specifically for remote extraction.
Belkasoft Incident InvestigationsBelkasoftTriageEfficiently investigate hacking attempts of Windows computers.
Belkasoft TriageBelkasoftTriagePerform effective triage analysis of Windows devices right on the incident scene.
Belkasoft RAM Capturer: Volatile Memory Acquisition ToolBelkasoftData AcquisitionBelkasoft Live RAM Capturer is a tiny free forensic tool that allows to reliably extract the entire contents of computer’s volatile memory—even if protected by an active anti-debugging or anti-dumping system.
Blue Team App Office 365 and AzureInvictus Incident ResponseCloud & SaaSThe Blue team app for Office 365 and Azure is developed to help you investigate the Microsoft 365 Audit log.
AutopsyBrian CarrierDigital ForensicsAutopsy is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools.
The Sleuth KitBrian CarrierDigital ForensicsThe Sleuth Kit (TSK) is a library and collection of command line tools that allow you to investigate disk images. The core functionality of TSK allows you to analyze volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
bulk_extractorDr. Simson GarfinkelDigital Forensicsbulk_extractor is a high-performance digital forensics exploitation tool. It is a "get evidence" button that rapidly scans any kind of input (disk images, files, directories of files, etc) and extracts structured information such as email addresses, credit card numbers, JPEGs and JSON snippets without parsing the file system or file system structures.
ChainsawWithSecureLabsTriageRapidly Search and Hunt through Windows Forensic Artefacts.
Cellebrite Digital CollectorCellebriteData AcquisitionA powerful forensic imaging software solution to perform triage, live data acquisition and targeted data collection for Windows and Mac computers.
Cellebrite InspectorCellebriteDigital ForensicsAll the functionality you need to conduct in-depth analysis and generate custom reports to reveal the truth.
Cellebrite Physical AnalyzerCellebriteDigital ForensicsSurface actionable intelligence from the broadest range of digital devices, applications, warrant returns and the Cloud, to work smarter and faster.
Cellebrite UFEDCellebriteData AcquisitionCollect data from the widest range of digital devices.
cLeappMark McKinnonTriageChrome Logs Events and Protobuf Parser.
CyLRAlan Orlikoski & Jason YeggeTriageCyLR - Live Response Collection Tool.
Cyber TriageBrian CarrierTriageCyber Triage is automated Digital Forensics and Incident Response (DFIR) software that allows cybersecurity professionals like you to quickly answer intrusion questions related to malware, ransomware, and account takeover.
FTK Forensic ToolkitExterroDigital ForensicsThe gold standard in digital forensics software for repeatable, defensible full-disk image collection, processing and review.
DFIR-IRISDFIR-IRISIncident ResponseIRIS is a collaborative platform aiming to help incident responders to share technical details during investigations.
Directory OPUSGP SoftwareUtilitiesDirectory Opus is a complete replacement for Explorer, with far more functionality than any other file manager available today.
DriveFS SleuthAmged WagehCloud & SaaSDriveFS Sleuth is a Python tool that automates investigating Google Drive File Stream disk artifacts, the tool has been developed based on research that has been performed by mounting different scenarios and noting down the changes in the Google Drive File Stream disk artifacts.
EditPad ProJust Great SoftwareUtilitiesEditPad Pro is a powerful and versatile text editor or word processor.
Browser History ViewerFoxtron ForensicsDigital ForensicsBrowser History Viewer allows you to easily view internet history from the main desktop web browsers.
Eric Zimmerman's ToolsEric ZimmermanTriageEric Zimmerman's suite of forensic tools which includes artifact parsing tools and GUIs for raw artifact analysis.
Event Log ExplorerFSPro LabsWindows Artifact AnalysisEvent Log Explorer is an effective software solution for viewing, analyzing and monitoring events recorded in Microsoft Windows event logs.
EventTranscriptParserAbhiram Kumar PatiballaWindows Artifact AnalysisPython based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data).
EverythingVoidtoolsUtilitiesLocate files and folders by name instantly.
F-ResponseF-ResponseData AcquisitionLive forensics, data recovery and eDiscovery over an IP network - using your choice of tools.
Flare-VMMandiantMalware AnalysisA collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.
MAGNET AxiomMAGNET ForensicsDigital ForensicsExamine digital evidence from mobile, cloud, computer, and vehicle sources, alongside third-party extractions all in one case file.
FTK ImagerExterroData AcquisitionFTK Imager is a data preview and imaging tool used to acquire digital evidence in a forensically sound manner by creating copies of data without changing the original in any way.
GAMJay LeeCloud & SaaSGAM is a command line tool for Google Workspace admins to manage domain and user settings quickly and easily.
HayabusaYamamoto SecurityTriageHayabusa is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Hibernation ReconArsenal ReconUtilitiesHibernation Recon not only supports active memory reconstruction from Windows XP, Vista, 7, 8/8.1, 10, and 11 hibernation files, but also extracts massive volumes of information from the multiple types (and levels) of slack space that may exist within them.
EnCase ForensicOpenTextDigital ForensicsEnCase Forensic is the global standard in digital investigation technology for forensic practitioners who need to conduct efficient, forensically-sound data collection and investigations using a repeatable and defensible process.
INDXRipperHarel SegevWindows Artifact AnalysisCarve file metadata from NTFS index ($I30) attributes.
iLEAPPAlexis BrignoniMobile ForensicsiOS Logs, Events, And Plist Parser.
Invictus-AWSInvictus Incident ResponseCloud & SaaSA tool for AWS incident response, that allows for enumeration, acquisition and analysis of data from AWS environments for the purpose of incident response.
KansaDave HullIncident ResponseA Powershell incident response framework.
KAPEEric ZimmermanTriageKroll Artifact Parser and Extractor (KAPE) is an efficient and highly configurable triage program that will target essentially any device or storage location, find forensically useful artifacts, and parse them within a few minutes.
lLeappMark McKinnonTriageLinux Logs Events Application Program Parser.
MAGNET AcquireMAGNET ForensicsData AcquisitionMagnet Acquire lets digital forensic examiners quickly and easily acquire forensic images of any iOS or Android device, hard drive, and removable media — and is available at no cost to the forensic community.
SIFT WorkstationRob LeeDigital ForensicsThe SIFT Workstation is a collection of free and open-source incident response and forensic tools designed to perform detailed digital forensic examinations in a variety of settings.
MAGNET DumpIt for LinuxMAGNET ForensicsData AcquisitionMemory acquisition for Linux that makes sense.
MAGNET DumpIt for WindowsMAGNET ForensicsData AcquisitionDumpIt is a fast memory acquisition tool for Windows (x86, x64, ARM64). Generate full memory crash dumps of Windows machines.
MAGNET Process CaptureMAGNET ForensicsData AcquisitionMagnet Process Capture is a free tool that allows you to capture memory from individual running processes.
MAGNET RAM CaptureMAGNET ForensicsData AcquisitionMagnet RAM Capture is a free imaging tool designed to capture the physical memory of a suspect’s computer, allowing investigators to recover and analyze valuable artifacts that are often only found in memory.
mboxviewereneamCloud & SaaSA simple viewer to view mbox files such as Thunderbird Archives, Google mail archives or simple Eml files.
MemProcFSUlf FriskMemory ForensicsMemProcFS is an easy and convenient way of viewing physical memory as files in a virtual file system.
MFT_BrowserCostas KatsavounidisWindows Artifact Analysis$MFT directory tree reconstruction & FILE record info.
Mft2CsvJörg SchichtWindows Artifact AnalysisExtract $MFT record info and log it to a csv file.
Microsoft Extractor SuiteInvictus Incident ResponseCloud & SaaSA PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.
NirSoftNirSoftTriageNirSoft's Forensics utilities suite.
OneDriveExplorerBrian MaloneyCloud & SaaSOneDriveExplorer is a command line and GUI based application for reconstructing the folder structure of OneDrive from the .dat and .dat.previous file.
PCAParserAndrew RathbunWindows Artifact AnalysisA PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca.
PlasoKristinn GuðjónssonTimeline AnalysisPlaso, or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines.
PowerToysMicrosoftUtilitiesMicrosoft PowerToys is a set of utilities for power users to tune and streamline their Windows experience for greater productivity.
Rapid Endpoint InvestigationsSecure CakeTriageScripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE.
RDPCacheStitcher Adam HarrisonWindows Artifact AnalysisRdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
reg_hunterThe FlakesTriageBlueteam operational triage registry hunting/forensic tool.
RegRipperHarlen CarveyWindows Artifact AnalysisOpen-source tool, written in Perl, for extracting/parsing information (key, values, data) from the registry and presenting it for analysis.
RegshotPara and TiANWEiWindows Artifact AnalysisRegshot is a small, free and open-source registry compare utility that allows you to quickly take a snapshot of your registry and then compare it with a second one - done after doing system changes or installing a new software product.
REMnuxLenny ZeltserMalware AnalysisA Linux Toolkit for Malware Analysis.
RLEAPPAlexis BrignoniTriageReturns Logs Events And Properties Parser.
ShareXJaexUtilitiesScreen capture, file sharing and productivity tool.
HindsightRyan BensonDigital ForensicsWeb browser forensics for Google Chrome/Chromium.
SnagitTechsmithUtilitiesThe ultimate screen capture & video recording tool for Windows and Mac.
SOF-ELKPhil HagenIncident ResponseSOF-ELK is a “big data analytics” platform focused on the typical needs of computer forensic investigators/analysts and information security operations personnel.
TZworksTZWorksDigital ForensicsSuite of forensic tools that either (a) simplify the investigative process, (b) provide new automated capabilities where only manual techniques were available or (c) reverse engineer a new aspect of the operating system to give new artifact analysis capabilities where none existed before.
THOR APT ScannerNextron SystemsTriageTHOR is the most sophisticated and flexible compromise assessment tool on the market.
THOR Lite Free IOC and YARA ScannerNextron SystemsTriageTHOR Lite includes the file system and process scan module as well as module that extracts “autoruns” information on the different platforms.
Thumbcache ViewerEric ZimmermanWindows Artifact AnalysisThumbcache Viewer allows you to extract thumbnail images from the thumbcache_*.db and iconcache_*.db database files found on Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, and Windows 11.
Thumbs ViewerJan LibicekWindows Artifact AnalysisThumbs Viewer allows you to extract thumbnail images from the Thumbs.db, ehthumbs.db, ehthumbs_vista.db, Image.db, Video.db, TVThumb.db, and musicThumbs.db database files found on various Windows operating systems.
TimesketchJohan BerggrenTimeline AnalysisTimesketch is an open-source tool for collaborative forensic timeline analysis.
TRACERadoslav GadzhovskiWindows Artifact AnalysisTRACE is a digital forensic analysis tool that provides a user-friendly interface for investigating disk images.
DB Browser for SQLiteVariousDigital ForensicsDB Browser for SQLite (DB4S) is a high quality, visual, open source tool designed for people who want to create, search, and edit SQLite database files.
UACThiago Canozzo LahrTriageUAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
unix_collectorJerzy 'Yuri' KramarzTriageunix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries.
USB DetectiveJason HaleWindows Artifact AnalysisUSB Detective is an application for identifying, investigating, and reporting on USB storage devices that have been connected to a Windows system.
Usnjrnl RewindCyberCXWindows Artifact AnalysisThis script will process the outputs of Eric Zimmerman's MFTEcmd tool and produce a csv that has the complete and correct path for every file and folder (no more Unknowns).
VelociraptorVelocidexIncident ResponseVelociraptor is an advanced digital forensic and incident response tool that enhances your visibility into your endpoints.
Volatility 2Volatility FoundationMemory ForensicsVolatility is the world's most widely used framework for extracting digital artifacts from volatile memory (RAM) samples.
Volatility 3Volatility FoundationMemory ForensicsVolatility is the world's most widely used framework for extracting digital artifacts from volatile memory (RAM) samples.
Volatility WorkbenchPassMark SoftwareMemory ForensicsVolatility Workbench is a graphical user interface (GUI) for the Volatility tool. Volatility is a command line memory analysis and forensics tool for extracting artifacts from memory dumps. Volatility Workbench is free, open source and runs in Windows.
VLEAPPAlexis BrignoniTriageVehicle Logs Events And Properties Parser.
WazuhWazuh, Inc.Incident ResponseUnified XDR and SIEM protection for endpoints and cloud workloads.
WELAYamamoto SecurityTimeline AnalysisWELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs!
WinFETroy LarsonUtilitiesWindows Forensic Environment, also known as WinFE or Windows FE, was originally developed by Troy Larson, Senior Forensic Manager, Microsoft Corporation, by simply adding two registry keys to the Windows Vista Pre-installation Environment 2.0 (WinPE 2.0). These keys prevented the auto-mounting of some of the volumes at boot time, which then allowed the creation of a rudimentary Microsoft Windows based forensic boot CD/DVD or USB Device.
WinPmemVelocidexMemory ForensicsThe multi-platform memory acquisition tool.
WMI-ParserMark WoanWindows Artifact AnalysisParses the WMI object database....looking for persistence.
X-Ways ForensicsX-WaysDigital ForensicsX-Ways Forensics is an advanced work environment for computer forensic examiners and the flagship product.
X-Ways ImagerX-WaysData AcquisitionForensic disk imaging tool. Stripped down version of the X-Ways Forensics computer forensics software with just the disk imaging functionality and little more.