Home / Incident Management / Digital Forensics

Digital Forensics

Digital forensics for incident response. Uncover digital evidence to understand and resolve security breaches effectively.

Try these 212 AI Digital Forensics Tools

pcapfex
Free

pcapfex

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

PcapXray
Free

PcapXray

A repository containing material from a talk on sub-domain enumeration techniques

Penguin OS Forensic (or Flight) Recorder (POFR)
Free

Penguin OS Forensic (or Flight) Recorder (POFR)

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

PhotoRec
Free

PhotoRec

A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.

PII Tools
Free

PII Tools

A file search and query tool for ops and security experts.

Plaso
Free

Plaso

dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

PowerForensics
Free

PowerForensics

A Mac OS X computer forensics tool for analyzing system artifacts, user files, and logs with reputation verification and log aggregation capabilities.

PSRecon
Free

PSRecon

A utility for recovering deleted files from ext3 or ext4 partitions.

python-ntfs
Free

python-ntfs

Dump the contents of the location database files on iOS and macOS with output options like KML and CSV.

Radare2
Free

Radare2

dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

Razzer
Free

Razzer

A collection of tools for extracting and analyzing information from .git repositories

Recog
Free

Recog

Customizable live OS constructor tool for remote forensics and incident response.

Recon
Free

Recon

A network forensics tool for visualizing packet captures as network diagrams with detailed analysis.

RegRippy
Free

RegRippy

A library to access and parse Windows NT Registry File (REGF) format.

Rekall
Free

Rekall

A tool for extracting files from packet capture files with ease of use and extensibility for Python developers.

RegRipper 3.0
Free

RegRipper 3.0

Forensic imaging program with full hash authentication and various acquisition options.

Rifiuti2
Free

Rifiuti2

A powerful tool for analyzing and visualizing system activity timelines.

Rizin
Free

Rizin

A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.

second-order
Free

second-order

A shell script for basic forensic collection of various artefacts from UNIX systems.

ShadowCopy Analyzer
Free

ShadowCopy Analyzer

A Forensic Framework for Skype with various investigative options.

Silk Guardian
Free

Silk Guardian

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

Skadi
Free

Skadi

A library to access and parse Windows Shortcut File (LNK) format.