Home / Incident Management / Digital Forensics

Digital Forensics

Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.

Try these 212 AI Digital Forensics Tools

Hoarder
Free

Hoarder View Hoarder

A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.

ics_mem_collect
Free

ics_mem_collect View ics_mem_collect

Second-order subdomain takeover scanner

IE10Analyzer
Free

IE10Analyzer View IE10Analyzer

A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.

iLEAPP
Free

iLEAPP View iLEAPP

Forensic imaging program with full hash authentication and various acquisition options.

imobax
Free

imobax View imobax

A script for extracting common Windows artifacts from source images and VSCs with detailed dependencies and usage instructions.

imagemounter
Free

imagemounter View imagemounter

A tool with advanced filtering capabilities for analyzing events based on time, path, weekday, and date.

Incident Response & Computer Forensics, Third Edition
Free

Incident Response & Computer Forensics, Third Edition View Incident Response & Computer Forensics, Third Edition

A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.

iOS Frequent Locations Dumper
Free

iOS Frequent Locations Dumper View iOS Frequent Locations Dumper

Toolkit for performing acquisitions on iOS devices with logical and filesystem acquisition support.

iOSForensic
Free

iOSForensic View iOSForensic

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

iPBD2 - iPhone Backup Decoder and Analyzer
Free

iPBD2 - iPhone Backup Decoder and Analyzer View iPBD2 - iPhone Backup Decoder and Analyzer

Forensics tool for exploring offline Docker filesystems.

IPED Digital Forensic Tool
Free

IPED Digital Forensic Tool View IPED Digital Forensic Tool

TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.

IRTriage
Free

IRTriage View IRTriage

Tool for live forensics acquisition on Windows systems, collecting artefacts for early compromise detection.

jpeginfo
Free

jpeginfo View jpeginfo

A portable volatile memory acquisition tool for Linux.

Katana
Free

Katana View Katana

A modified version of GNU dd with added features like hashing and fast disk wiping.

kube-forensics
Free

kube-forensics View kube-forensics

Rekall is a discontinued project that aimed to improve memory analysis methodology but faced challenges due to the nature of in-memory structure and increasing security measures.

Kuiper Digital Investigation Platform
Free

Kuiper Digital Investigation Platform View Kuiper Digital Investigation Platform

ID-spoofing NFS client

LFI-Enum
Free

LFI-Enum View LFI-Enum

A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.

LfLe
Free

LfLe View LfLe

Orochi is a collaborative forensic memory dump analysis framework.

libesedb
Free

libesedb View libesedb

Collects and organizes Linux OS data for detailed analysis and incident response.

libfsapfs
Free

libfsapfs View libfsapfs

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

libfwnt
Free

libfwnt View libfwnt

A file search and query tool for ops and security experts.

libewf
Free

libewf View libewf

Comprehensive digital forensics and incident response platform for law enforcement, corporate, and academic institutions.

libevtx
Free

libevtx View libevtx

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.