Home / Incident Management / Digital Forensics

Digital Forensics

Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.

Try these 212 AI Digital Forensics Tools

evtkit
Free

evtkit

A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.

exif
Free

exif

A tool for restoring defocused and blurred images with various deconvolution techniques and fast processing capabilities.

Exiv2
Free

Exiv2

A user-friendly and fast Forensic Analysis tool with features like tagging files and generating preview reports.

Exterro
Free

Exterro

Toolkit for post-mortem analysis of Docker runtime environments using forensic HDD copies.

extundelete
Free

extundelete

A library to access and parse Windows XML Event Log (EVTX) format, useful for digital forensics and incident response.

eyeballer
Free

eyeballer

A community-sourced repository of digital forensic artifacts in YAML format.

Factual Rules Generator
Free

Factual Rules Generator

DMG2IMG is a tool for converting Apple compressed dmg archives to standard image disk files with support for zlib, bzip2, and LZFSE compression.

FastIR Collector
Free

FastIR Collector

A console program for file recovery through data carving.

FEX Imagerâ„¢
Free

FEX Imagerâ„¢

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

Foremost
Free

Foremost

Comprehensive digital forensics and incident response platform for law enforcement, corporate, and academic institutions.

ForensicMiner v1.4
Free

ForensicMiner v1.4

A Python-based engine for automatic creation of timelines in digital forensic analysis

Forensic Registry EDitor (FRED)
Free

Forensic Registry EDitor (FRED)

Web interface for the Volatility Memory Analysis framework with advanced features.

Forensia
Free

Forensia

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

Fridump
Free

Fridump

A library to access and parse Windows Shortcut File (LNK) format.

GitTools
Free

GitTools

A command line utility for managing volume shadow copies with capabilities for evasion, persistence, and file extraction.

gvfs
Free

gvfs

An anti-forensic kill-switch tool for USB ports to shut down the computer immediately in case of unauthorized access.

hashlookup-forensic-analyser
Free

hashlookup-forensic-analyser

A Python 2.x tool for memory analysis on Mac OS X systems with support for various OS versions and memory image export capabilities.

Hayabusa
Free

Hayabusa

A digital forensics tool that provides read-only access to file-system objects from various storage media types and file formats.

Hindsight
Free

Hindsight

A forensic tool to find hidden processes and TCP/UDP ports by rootkits or other hidden techniques.

hivex
Free

hivex

A digital forensic tool for creating forensic images of computer hard drives and analyzing digital evidence.