Home / Incident Management / Digital Forensics

Digital Forensics

Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.

Try these 212 AI Digital Forensics Tools

mem
Free

mem View mem

Windows event log fast forensics timeline generator and threat hunting tool.

MemProcFS
Free

MemProcFS View MemProcFS

A tool for collecting and analyzing screenshots from remote desktop protocols, web applications, and VNC connections.

MemLabs
Free

MemLabs View MemLabs

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

MFT Parsers Review
Free

MFT Parsers Review View MFT Parsers Review

Second-order subdomain takeover scanner

MFTExtractor
Free

MFTExtractor View MFTExtractor

A framework for orchestrating forensic collection, processing, and data export.

MFTMactime
Free

MFTMactime View MFTMactime

Collects and organizes Linux OS data for detailed analysis and incident response.

MFT_Browser
Free

MFT_Browser View MFT_Browser

A DFVFS backed viewer project with a WxPython GUI, aiming to enhance file extraction and viewing capabilities.

Mobile Verification Toolkit (MVT)
Free

Mobile Verification Toolkit (MVT) View Mobile Verification Toolkit (MVT)

Remote Acquisition Tool

mXtract
Free

mXtract View mXtract

An open source digital forensic tool for processing and analyzing digital evidence with high performance and multiplatform support.

nbdserver
Free

nbdserver View nbdserver

A reconnaissance tool for GitHub organizations

Network Appliance Forensic Toolkit
Free

Network Appliance Forensic Toolkit View Network Appliance Forensic Toolkit

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

nightHawk Response
Free

nightHawk Response View nightHawk Response

AMExtractor is an Android Memory Extractor tool.

nfspy
Free

nfspy View nfspy

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

Nomoreransom
Free

Nomoreransom View Nomoreransom

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

NTFS-Linker
Free

NTFS-Linker View NTFS-Linker

Second-order subdomain takeover scanner

nTimetools
Free

nTimetools View nTimetools

XMLStarlet offers a suite of command line utilities for manipulating and querying XML documents.

Open Backup Extractor
Free

Open Backup Extractor View Open Backup Extractor

A binary analysis platform for analyzing binary programs

Orochi
Free

Orochi View Orochi

A tool for discovering, analyzing, and remedying sensitive data

OS X Auditor
Free

OS X Auditor View OS X Auditor

A network forensics toolkit that transforms network traffic data into graph-based representations for interactive analysis and visualization through a web interface.

OTE
Free

OTE View OTE

A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.

OSXCollector
Free

OSXCollector View OSXCollector

IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.

Pancake Viewer
Free

Pancake Viewer View Pancake Viewer

Tool used for dumping memory from Android devices with root access requirement and forensic soundness considerations.

PANORAMA
Free

PANORAMA View PANORAMA

A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.

PassMark OSForensics
Free

PassMark OSForensics View PassMark OSForensics

IE10Analyzer can parse and recover records from WebCacheV01.dat, providing detailed information and conversion capabilities.