Home / Incident Management / Digital Forensics

Digital Forensics

Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.

Try these 212 AI Digital Forensics Tools

Hoarder
Free

Hoarder

A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.

IE10Analyzer
Free

IE10Analyzer

A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.

iLEAPP
Free

iLEAPP

Forensic imaging program with full hash authentication and various acquisition options.

imobax
Free

imobax

A script for extracting common Windows artifacts from source images and VSCs with detailed dependencies and usage instructions.

imagemounter
Free

imagemounter

A tool with advanced filtering capabilities for analyzing events based on time, path, weekday, and date.

Incident Response & Computer Forensics, Third Edition
Free

Incident Response & Computer Forensics, Third Edition

A PowerShell-based incident response and live forensic data acquisition tool for Windows hosts.

iOS Frequent Locations Dumper
Free

iOS Frequent Locations Dumper

Toolkit for performing acquisitions on iOS devices with logical and filesystem acquisition support.

iOSForensic
Free

iOSForensic

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

iPBD2 - iPhone Backup Decoder and Analyzer
Free

iPBD2 - iPhone Backup Decoder and Analyzer

Forensics tool for exploring offline Docker filesystems.

IPED Digital Forensic Tool
Free

IPED Digital Forensic Tool

TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.

IRTriage
Free

IRTriage

Tool for live forensics acquisition on Windows systems, collecting artefacts for early compromise detection.

Katana
Free

Katana

A modified version of GNU dd with added features like hashing and fast disk wiping.

kube-forensics
Free

kube-forensics

Rekall is a discontinued project that aimed to improve memory analysis methodology but faced challenges due to the nature of in-memory structure and increasing security measures.

LFI-Enum
Free

LFI-Enum

A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.

LfLe
Free

LfLe

Orochi is a collaborative forensic memory dump analysis framework.

libesedb
Free

libesedb

Collects and organizes Linux OS data for detailed analysis and incident response.

libfsapfs
Free

libfsapfs

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

libewf
Free

libewf

Comprehensive digital forensics and incident response platform for law enforcement, corporate, and academic institutions.

libevtx
Free

libevtx

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.