Home / Incident Management / Digital Forensics

Digital Forensics

Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.

Try these 212 AI Digital Forensics Tools

Acquire
Free

Acquire View Acquire

A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.

AChoir Windows Live Artifacts Acquisition Scripting Framework
Free

AChoir Windows Live Artifacts Acquisition Scripting Framework View AChoir Windows Live Artifacts Acquisition Scripting Framework

Second-order subdomain takeover scanner

AccessData FTK Imager
Free

AccessData FTK Imager View AccessData FTK Imager

Open Source computer forensics platform with modular design for easy automation and scripting.

ALEAPP Android Logs Events And Protobuf Parser
Free

ALEAPP Android Logs Events And Protobuf Parser View ALEAPP Android Logs Events And Protobuf Parser

Python tool for remote memory acquisition

Andriller CE (Community Edition)
Free

Andriller CE (Community Edition) View Andriller CE (Community Edition)

Recover event log entries from an image by heuristically looking for record structures.

AMExtractor
Free

AMExtractor View AMExtractor

A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.

Antivmdetection Background
Free

Antivmdetection Background View Antivmdetection Background

A console program for file recovery through data carving.

Aperi'Solve
Free

Aperi'Solve View Aperi'Solve

CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.

ArtifactExtractor
Free

ArtifactExtractor View ArtifactExtractor

A Windows Registry hive extraction library that reads and writes Windows Registry 'hive' binary files.

artifactcollector
Free

artifactcollector View artifactcollector

Windows event log fast forensics timeline generator and threat hunting tool.

AVML (Acquire Volatile Memory for Linux)
Free

AVML (Acquire Volatile Memory for Linux) View AVML (Acquire Volatile Memory for Linux)

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

Belkasoft
Free

Belkasoft View Belkasoft

A forensics tool for tracking USB device artifacts on Linux machines.

Belkasoft X Forensic
Free

Belkasoft X Forensic View Belkasoft X Forensic

A forensics tool for tracking USB device artifacts on Linux machines.

Belkasoft Evidence Center
Free

Belkasoft Evidence Center View Belkasoft Evidence Center

Web interface for the Volatility Memory Analysis framework with advanced features.

Bitscout
Free

Bitscout View Bitscout

Exiv2 is a C++ library and command-line utility for image metadata manipulation.

BloodHound
Free

BloodHound View BloodHound

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

BinaryAnalysisPlatform (BAP)
Free

BinaryAnalysisPlatform (BAP) View BinaryAnalysisPlatform (BAP)

A tool for triaging crash files with various output formats and debugging engine options.

Binalyze AIR
Free

Binalyze AIR View Binalyze AIR

A comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response and remediation.

bugcrowd-levelup-subdomain-enumeration
Free

bugcrowd-levelup-subdomain-enumeration View bugcrowd-levelup-subdomain-enumeration

A library to access and read QEMU Copy-On-Write (QCOW) image file formats with support for zlib compression and AES-CBC encryption.

bstrings
Free

bstrings View bstrings

A Python tool for in-depth PDF analysis and modification.

bulk_extractor
Free

bulk_extractor View bulk_extractor

A next-generation crawling and spidering framework for extracting data from websites

c-aff4
Free

c-aff4 View c-aff4

Tool for parsing NTFS journal files, $Logfile, and $MFT.

cabextract
Free

cabextract View cabextract

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.