Skip to content
77

Forensics Tools

A list of free and open forensics analysis tools and other resources

2.6k stars362 forks189 entriesLast push Jul 9, 2026 (2 months ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Collections

DFIR – The definitive compendium project

Collection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more

In 2 lists

DFIR-SQL-Query-Repo

Collection of SQL queries templates for digital forensics use by platform and application.

dfir.training

Database of forensic resources focused on events, tools and more

Tools

Forensics tools on Wikipedia

Eric Zimmerman's Tools

An updated list of forensic tools created by Eric Zimmerman, an instructor for SANS institute.

In 3 lists

Challenges

Blue Team Labs Online

Challenges >Distributions

bitscout

LiveCD/LiveUSB for remote forensic acquisition and analysis

In 2 lists

CAINE

CAINE is a Ubuntu-based app that offers a complete forensic environment that provides a graphical interface. This tool can be integrated into existing software tools as a module. It automatically extracts a timeline from RAM.

In 4 lists

GRML-Forensic

Remnux

Distro for reverse-engineering and analyzing malicious software

In 5 listsDetails

Santoku Linux

Santoku is dedicated to mobile forensics, analysis, and security, and packaged in an easy to use, Open Source platform.

In 3 lists

Sumuri Paladin

Linux distribution that simplifies various forensics tasks in a forensically sound manner via the PALADIN Toolbox

In 2 lists

Tsurugi Linux

Linux distribution for forensic analysis

In 5 listsDetails

WinFE

Windows Forensics enviroment

Predator OS

Linux distribution for forensic analysis

Challenges >Frameworks

dff

Forensic framework

dexter

Dexter is a forensics acquisition framework designed to be extensible and secure

IntelMQ

IntelMQ collects and processes security feeds

In 2 lists

Kuiper

Digital Investigation Platform

In 2 lists

Laika BOSS

Laika is an object scanner and intrusion detection system

In 3 lists

RegRippy

is a framework for reading and extracting useful forensics data from Windows registry hives.

PowerForensics

PowerForensics is a framework for live disk forensic analysis

In 6 listsDetails

turbinia

Turbinia is an open-source framework for deploying, managing, and running forensic workloads on cloud platforms

In 2 lists

IPED - Indexador e Processador de Evidências Digitais

Brazilian Federal Police Tool for Forensic Investigations

In 3 lists

Challenges >Live forensics

grr

GRR Rapid Response: remote live forensics for incident response

In 6 listsDetails

Linux Expl0rer

Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask

In 3 lists

mig

Distributed & real time digital forensics at the speed of the cloud

osquery

SQL powered operating system analytics

In 6 listsDetails

Challenges >Acquisition

artifactcollector

A customizable agent to collect forensic artifacts on any Windows, macOS or Linux system

In 2 lists

ArtifactExtractor

Extract common Windows artifacts from source images and VSCs

AVML

A portable volatile memory acquisition tool for Linux

In 3 lists

DFIR ORC

Forensics artefact collection tool for systems running Microsoft Windows

In 2 lists

DumpIt

FastIR Collector

Collect artifacts on windows

In 2 lists

FireEye Memoryze

Free memory forensic software that helps incident responders find evil in live memory. Memoryze can acquire and/or analyze memory images, and on live systems, can include the paging file in its analysis.

In 2 lists

Fuji

Graphical interface for the forensic logical acquisition of Mac computers

LiME

Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD

In 4 lists

Magnet RAM Capture

is a free imaging tool designed to capture the physical memory

UFADE

Extract files from Apple devices on Windows, Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates iTunes-style backups and "advanced logical backups"

Velociraptor

Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries

In 5 listsDetails

Challenges >Imageing

dc3dd

Improved version of dd

dcfldd

Different improved version of dd (this version has some bugs!, another version is on github adulau/dcfldd)

FTK Imager

Free imageing tool for windows

Challenges >Carving

bstrings

Improved strings utility

bulk_extractor

Extracts informations like email adresses, creditscard numbers and histrograms of disk images

In 6 listsDetails

floss

Static analysis tool to automatically deobfuscate strings from malware binaries

In 2 lists

swap_digger

A bash script used to automate Linux swap analysis, automating swap extraction and searches for Linux user credentials, Web form credentials, Web form emails, etc.

In 2 lists

Challenges >Memory Forensics

FireEye RedLine

provides host investigative capabilities to users to find signs of malicious activity through memory and file analysis and the development of a threat assessment profile.

In 4 lists

inVtero.net

High speed memory analysis framework developed in .NET supports all Windows x64, includes code integrity and write support

In 3 lists

KeeFarce

Extract KeePass passwords from memory

MemProcFS

An easy and convenient way of accessing physical memory as files a virtual file system.

In 3 lists

MemPrcFs Analyzer

PowerShell script utilized to simplify the usage of MemProcFS and to optimize your memory analysis workflow.

In 2 lists

Rekall

Memory Forensic Framework

In 3 lists

VolUtility

Web App for Volatility framework

In 2 lists

Challenges >Network Forensics

NetworkMiner

Xplico

In 2 lists

Challenges >Windows Artifacts

Beagle

Transform data sources and logs into graphs

CrowdResponse

by CrowdStrike is a static host data collection tool

FRED

Cross-platform microsoft registry hive editor

LastActivityView

LastActivityView by Nirsoftis a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer.

LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log

In 5 listsDetails

python-evt

Pure Python parser for classic Windows Event Log files (.evt)

In 2 lists

RegRipper3.0

RegRipper is an open source Perl tool for parsing the Registry and presenting it for analysis.

In 2 lists

MFT-Parsers

Comparison of MFT-Parsers

MFTExtractor

MFT-Parser

NTFS journal parser

NTFSTool

Complete NTFS forensics tool

In 3 lists

NTFS USN Journal parser

RecuperaBit

Reconstruct and recover NTFS data

In 2 lists

python-ntfs

NTFS analysis

Challenges >Linux Forensics

FJTA - Forensic Journal Timeline Analyzer

Tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities

In 2 lists

Challenges >OS X Forensics

APFS Fuse

is a read-only FUSE driver for the new Apple File System

APOLLO

Disk-Arbitrator

is a Mac OS X forensic utility designed to help the user ensure correct forensic procedures are followed during imaging of a disk device

MAC OSX Artifacts

locations artifacts by mac4n6 group

mac_apt (macOS Artifact Parsing Tool)

Extracts forensic artifacts from disk images or live machines

In 4 lists

MacLocationsScraper

Dump the contents of the location database files on iOS and macOS.

macMRUParser

Python script to parse the Most Recently Used (MRU) plist files on macOS into a more human friendly format.

MacOs Analyzer Suite

A collection of PowerShell scripts for analyzing macOS Forensic Artifacts

MacOs Collector

Shell script utilized to collect macOS Forensic Artifacts from a compromised macOS endpoint

OSXAuditor

Free Mac OS X computer forensics tool.

In 5 listsDetails

OSX Collect

Forensic evidence collection & analysis toolkit for macOS.

In 6 listsDetails

Challenges >Mobile Forensics

Andriller

is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices

In 4 listsDetails

ALEAPP

An Android Logs Events and Protobuf Parser

iOS Frequent Locations Dumper

Dump the contents of the StateModel#.archive files located in /private/var/mobile/Library/Caches/com.apple.routined/

In 2 lists

MEAT

Perform different kinds of acquisitions on iOS devices

In 2 lists

MobSF

is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

In 5 listsDetails

OpenBackupExtractor

is an app for extracting data from iPhone and iPad backups.

Challenges >Docker Forensics

dof (Docker Forensics Toolkit)

Extracts and interprets forensic artifacts from disk images of Docker Host systems

In 2 lists

Docker Explorer

Extracts and interprets forensic artifacts from disk images of Docker Host systems

In 2 lists

Challenges >Browser Artifacts

ChromeCacheView

by Nirsoft is a small utility that reads the cache folder of Google Chrome Web browser, and displays the list of all files currently stored in the cache

chrome-url-dumper

Dump all local stored infromation collected by Chrome

Dumpzilla

extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

hindsight

Internet history forensics for Google Chrome/Chromium

In 2 lists

unfurl

Extract and visualize data from URLs

mozdmp

Offline profile decryption tool for Mozilla Firefox. Supports multi-core CPU-based cracking of the master password and the latest Firefox hash formats, including those not yet supported by Hashcat and JTR.

chrdmp

Decrypt Chrome profile data offline using the Chrome Safe Storage keyring secret.

Challenges >Timeline Analysis

DFTimewolf

Framework for orchestrating forensic collection, processing and data export using GRR and Rekall

In 2 lists

timeliner

A rewrite of mactime, a bodyfile reader

timesketch

Collaborative forensic timeline analysis

In 5 listsDetails

Challenges >Disk image handling

Disk-Arbitrator

is a Mac OS X forensic utility designed to help the user ensure correct forensic procedures are followed during imaging of a disk device

imagemounter

Command line utility and Python package to ease the (un)mounting of forensic disk images

In 3 lists

libewf

Libewf is a library and some tools to access the Expert Witness Compression Format (EWF, E01)

OSFMount

allows you to mount local disk image files (bit-for-bit copies of an entire disk or disk partition) in Windows as a physical disk or a logical drive

In 2 lists

PancakeViewer

Disk image viewer based in dfvfs, similar to the FTK Imager viewer.

xmount

Convert between different disk image formats

Challenges >Decryption

hashcat

Fast password cracker with GPU support

In 3 lists

John the Ripper

Password cracker

Challenges >Management

dfirtrack

Digital Forensics and Incident Response Tracking application, track systems

Incidents

Web application for organizing non-trivial security investigations. Built on the idea that incidents are trees of tickets, where some tickets are leads

Challenges >Picture Analysis

Ghiro

is a fully automated tool designed to run forensics analysis over a massive amount of images

sherloq

An open-source digital photographic image forensic toolset

In 3 lists

Challenges >Steganography

Binwalk

Binwalk is a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.

In 6 listsDetails

Foremost

is a program to recover files based on their headers and footers

In 2 lists

Sonicvisualizer

An application for viewing and analysing the contents of music audio files.

In 2 lists

Steghide

is a steganography program that hides data in various kinds of image and audio files

Stegsolve

analyze images in different planes by taking off bits of the image

In 2 lists

Wavsteg

is a steganography program that hides data in various kinds of image and audio files

Zsteg

A steganographic coder for WAV files

In 2 lists

Audacity

an easy-to-use, multi-track audio editor and recorder

In 11 listsDetails

Challenges >Metadata Forensics

ExifTool

by Phil Harvey

In 4 listsDetails

Exiv2

Exiv2 is a Cross-platform C++ library and a command line utility to manage image metadata

FOCA

FOCA is a tool used mainly to find metadata and hidden information in the documents

In 4 listsDetails

Challenges >Website Forensics

Freezing Internet Tool

Python 3 application for forensic acquisition of online content, including web pages, emails, and social media.

ScanMalware

Scan websites for malicious behaviours and fingerprint JavaScripts.

In 2 lists

Learn forensics

Forensic challenges

Mindmap of forensic challenges

OpenLearn

Digital forensic course

Training material

Online training material by European Union Agency for Network and Information Security for different topics (e.g. Digital forensics, Network forensics)

Learn forensics >Challenges

AnalystUnknown Cyber Range

Champlain College DFIR CTF

Corelight CTF

CyberDefenders

Blue team challenges including OSINT.

In 2 lists

DefCon CTFs

archive of DEF CON CTF challenges.

Forensics CTFs

A curated list of CTF frameworks, libraries, resources and softwares

In 5 listsDetails

IncidentResponse Challenge

MagnetForensics CTF Challenge

MalwareTech Challenges

MalwareTraffic Analysis

MemLabs

NW3C Chanllenges

PivotProject

Precision Widgets of North Dakota Intrusion

ReverseEngineering Challenges

In 2 lists

SANS Forensics Challenges

Resources >Webs

ForensicsFocus

InsecInstitute Resources

In 2 lists

SANS Digital Forensics

Resources >Blogs

Cyberforensics

Cyberforensicator

DigitalForensicsMagazine

FlashbackData

Netresec

roDigitalForensics

SANS Forensics Blog

SecurityAffairs

blog by Pierluigi Paganini

Zena Forensics

In 2 lists

Resources >Books

Network Forensics: Tracking Hackers through Cyberspace

Learn to recognize hackers’ tracks and uncover network-based evidence

The Art of Memory Forensics

Detecting Malware and Threats in Windows, Linux, and Mac Memory

The Practice of Network Security Monitoring

Understanding Incident Detection and Response

Cell Phone Investigations: Search Warrants, Cell Sites and Evidence Recovery

Cell Phone Investigations is the most comprehensive book written on cell phones, cell sites, and cell related data.

Resources >File System Corpora

Digital Forensic Challenge Images

Two DFIR challenges with images

Digital Forensics Tool Testing Images

FAU Open Research Challenge Digital Forensics

The CFReDS Project

Hacking Case (4.5 GB NTFS Image)

Resources >Twitter

@4n6ist

@aheadless

@AppleExaminer

Apple OS X & iOS Digital Forensics

@blackbagtech

@carrier4n6

Brian Carrier, author of Autopsy and the Sleuth Kit

@CindyMurph

Detective & Digital Forensic Examiner

@EricRZimmerman

Certified SANS Instructor

@forensikblog

Computer forensic geek

@HECFBlog

SANS Certified Instructor

@Hexacorn

DFIR+Malware

@hiddenillusion

@iamevltwin

Mac Nerd, Forensic Analyst, Author & Instructor of SANS FOR518

@jaredcatkinson

PowerShell Forensics

@maridegrazia

Computer Forensics Examiner

@sleuthkit

@williballenthin

@XWaysGuide

Resources >Other

/r/computerforensics/

Subreddit for computer forensics

In 2 lists

ForensicControl

ForensicPosters

Posters of file system structures

HFS+ Resources

mac4n6 Presentations

Presentation Archives for OS X and iOS Related Research

SANS Forensics CheatSheets

Different CheatSheets from SANS

SANS Digital Forensics Posters

Digital Forensics Posters from SANS

SANS WhitePapers

White Papers written by forensic practitioners seeking GCFA, GCFE, and GREM Gold

See category
94

Awesome Mac

jaywcjlove/awesome-mac

 This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.

Fresh★ 115k1316 entriesPushed today
91

Open Source Mac Os Apps

serhii-londar/open-source-mac-os-apps

🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps

Fresh★ 51k700 entriesPushed 20 days ago
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
90

Awesome Nodejs

sindresorhus/awesome-nodejs

:zap: Delightful Node.js packages and resources [BECAUSE OF TOO MUCH SPAM AND LOW-QUALITY SUBMISSIONS, SUBMISSIONS ARE PAUSED TEMPORARILY]

Fresh★ 67k588 entriesPushed 28 days ago
90

Awesome Home Assistant

frenck/awesome-home-assistant

A curated list of amazingly awesome Home Assistant resources.

Fresh★ 8.5k312 entriesPushed 2 days ago
90

Awesome Ios

vsouza/awesome-ios

A curated list of awesome iOS ecosystem, including Objective-C and Swift Projects

Fresh★ 53k1812 entriesPushed 1 month ago