Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
ForensicsTools
A list of free and open forensics analysis tools and other resources
https://github.com/mesquidar/ForensicsTools
Last synced: 1 day ago
JSON representation
-
Collections
- DFIR-SQL-Query-Repo - Collection of SQL queries templates for digital forensics use by platform and application.
- ForensicArtifacts.com Artifact Repository - Machine-readable knowledge base of forensic artifacts
- dfir.training - Database of forensic resources focused on events, tools and more
-
Challenges
-
Distributions
- bitscout - LiveCD/LiveUSB for remote forensic acquisition and analysis
- SANS Investigative Forensics Toolkit (sift) - Linux distribution for forensic analysis
- CAINE
- GRML-Forensic
- Remnux - Distro for reverse-engineering and analyzing malicious software
- Santoku Linux - Santoku is dedicated to mobile forensics, analysis, and security, and packaged in an easy to use, Open Source platform.
- Sumuri Paladin - Linux distribution that simplifies various forensics tasks in a forensically sound manner via the PALADIN Toolbox
- Tsurugi Linux - Linux distribution for forensic analysis
- WinFE - Windows Forensics enviroment
-
Frameworks
- dff - Forensic framework
- dexter - Dexter is a forensics acquisition framework designed to be extensible and secure
- IntelMQ - IntelMQ collects and processes security feeds
- Kuiper - Digital Investigation Platform
- Laika BOSS - Laika is an object scanner and intrusion detection system
- RegRippy - is a framework for reading and extracting useful forensics data from Windows registry hives.
- PowerForensics - PowerForensics is a framework for live disk forensic analysis
- The Sleuth Kit - Tools for low level forensic analysis
- turbinia - Turbinia is an open-source framework for deploying, managing, and running forensic workloads on cloud platforms
- IPED - Indexador e Processador de Evidências Digitais - Brazilian Federal Police Tool for Forensic Investigations
- Autopsy - SleuthKit GUI
-
Live forensics
- grr - GRR Rapid Response: remote live forensics for incident response
- Linux Expl0rer - Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask
- mig - Distributed & real time digital forensics at the speed of the cloud
- osquery - SQL powered operating system analytics
-
Acquisition
- artifactcollector - A customizable agent to collect forensic artifacts on any Windows, macOS or Linux system
- ArtifactExtractor - Extract common Windows artifacts from source images and VSCs
- AVML - A portable volatile memory acquisition tool for Linux
- FastIR Collector - Collect artifacts on windows
- LiME - Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD
- Velociraptor - Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries
- DFIR ORC - Forensics artefact collection tool for systems running Microsoft Windows
- DumpIt
- Magnet RAM Capture - is a free imaging tool designed to capture the physical memory
- RAM Capturer - by Belkasoft is a free tool to dump the data from a computer’s volatile memory. It’s compatible with Windows OS.
-
Carving
- bstrings - Improved strings utility
- bulk_extractor - Extracts informations like email adresses, creditscard numbers and histrograms of disk images
- swap_digger - A bash script used to automate Linux swap analysis, automating swap extraction and searches for Linux user credentials, Web form credentials, Web form emails, etc.
- floss - Static analysis tool to automatically deobfuscate strings from malware binaries
- photorec - File carving tool
-
Memory Forensics
- inVtero.net - High speed memory analysis framework
- KeeFarce - Extract KeePass passwords from memory
- MemProcFS - An easy and convenient way of accessing physical memory as files a virtual file system.
- Rekall - Memory Forensic Framework
- volatility - The memory forensic framework
- VolUtility - Web App for Volatility framework
-
Network Forensics
-
Windows Artifacts
- Beagle - Transform data sources and logs into graphs
- LogonTracer - Investigate malicious Windows logon by visualizing and analyzing Windows event log
- python-evt - Pure Python parser for classic Windows Event Log files (.evt)
- RegRipper3.0 - RegRipper is an open source Perl tool for parsing the Registry and presenting it for analysis.
- MFTExtractor - MFT-Parser
- NTFS journal parser
- NTFS USN Journal parser
- RecuperaBit - Reconstruct and recover NTFS data
- python-ntfs - NTFS analysis
- MFT-Parsers - Comparison of MFT-Parsers
- CrowdResponse - by CrowdStrike is a static host data collection tool
- FRED - Cross-platform microsoft registry hive editor
- LastActivityView - LastActivityView by Nirsoftis a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer.
-
OS X Forensics
- APFS Fuse - is a read-only FUSE driver for the new Apple File System
- APOLLO
- mac_apt (macOS Artifact Parsing Tool) - Extracts forensic artifacts from disk images or live machines
- MacLocationsScraper - Dump the contents of the location database files on iOS and macOS.
- macMRUParser - Python script to parse the Most Recently Used (MRU) plist files on macOS into a more human friendly format.
- OSXAuditor
- OSX Collect
- MAC OSX Artifacts - locations artifacts by mac4n6 group
-
Mobile Forensics
- Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices
- ALEAPP - An Android Logs Events and Protobuf Parser
- iOS Frequent Locations Dumper - Dump the contents of the StateModel#.archive files located in /private/var/mobile/Library/Caches/com.apple.routined/
- MEAT - Perform different kinds of acquisitions on iOS devices
- MobSF - is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
- OpenBackupExtractor - is an app for extracting data from iPhone and iPad backups.
-
Docker Forensics
- dof (Docker Forensics Toolkit) - Extracts and interprets forensic artifacts from disk images of Docker Host systems
- Docker Explorer
-
Browser Artifacts
- chrome-url-dumper - Dump all local stored infromation collected by Chrome
- hindsight - Internet history forensics for Google Chrome/Chromium
- unfurl - Extract and visualize data from URLs
- ChromeCacheView - by Nirsoft is a small utility that reads the cache folder of Google Chrome Web browser, and displays the list of all files currently stored in the cache
- Dumpzilla - extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers
-
Timeline Analysis
- DFTimewolf - Framework for orchestrating forensic collection, processing and data export using GRR and Rekall
- plaso - Extract timestamps from various files and aggregate them
- timeliner - A rewrite of mactime, a bodyfile reader
- timesketch - Collaborative forensic timeline analysis
-
Disk image handling
- Disk Arbitrator - A Mac OS X forensic utility designed to help the user ensure correct forensic procedures are followed during imaging of a disk device
- imagemounter - Command line utility and Python package to ease the (un)mounting of forensic disk images
- libewf - Libewf is a library and some tools to access the Expert Witness Compression Format (EWF, E01)
- PancakeViewer - Disk image viewer based in dfvfs, similar to the FTK Imager viewer.
- OSFMount - allows you to mount local disk image files (bit-for-bit copies of an entire disk or disk partition) in Windows as a physical disk or a logical drive
- xmount - Convert between different disk image formats
-
Management
-
Picture Analysis
-
Steganography
- Binwalk - Binwalk is a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.
- Foremost - is a program to recover files based on their headers and footers
- Steghide - is a steganography program that hides data in various kinds of image and audio files
- Wavsteg - is a steganography program that hides data in various kinds of image and audio files
- Zsteg - A steganographic coder for WAV files
- Stegsolve - analyze images in different planes by taking off bits of the image
-
Metadata Forensics
-
Imageing
- BelkaImager - by Belkasoft allows you to create images of hard and removable disks, Android and iOS devices and download data from the cloud.
- dc3dd - Improved version of dd
- Guymager - Open source version for disk imageing on linux systems
-
Decryption
- hashcat - Fast password cracker with GPU support
- John the Ripper - Password cracker
-
-
Learn forensics
-
Challenges
-
Website Forensics
- Forensic challenges - Mindmap of forensic challenges
- OpenLearn - Digital forensic course
-
-
Resources
-
Other
- ForensicPosters - Posters of file system structures
- HFS+ Resources
- mac4n6 Presentations - Presentation Archives for OS X and iOS Related Research
- /r/computerforensics/ - Subreddit for computer forensics
- ForensicControl
- SANS Forensics CheatSheets - Different CheatSheets from SANS
- SANS Digital Forensics Posters - Digital Forensics Posters from SANS
-
Webs
-
Blogs
-
Books
- The Art of Memory Forensics - Detecting Malware and Threats in Windows, Linux, and Mac Memory
- The Practice of Network Security Monitoring - Understanding Incident Detection and Response
- Cell Phone Investigations: Search Warrants, Cell Sites and Evidence Recovery - Cell Phone Investigations is the most comprehensive book written on cell phones, cell sites, and cell related data.
-
File System Corpora
- Digital Forensic Challenge Images - Two DFIR challenges with images
- Digital Forensics Tool Testing Images
- FAU Open Research Challenge Digital Forensics
-
Twitter
- @4n6ist
- @aheadless
- @AppleExaminer - Apple OS X & iOS Digital Forensics
- @blackbagtech
- @carrier4n6 - Brian Carrier, author of Autopsy and the Sleuth Kit
- @CindyMurph - Detective & Digital Forensic Examiner
- @EricRZimmerman - Certified SANS Instructor
- @forensikblog - Computer forensic geek
- @HECFBlog - SANS Certified Instructor
- @Hexacorn - DFIR+Malware
- @hiddenillusion
- @iamevltwin - Mac Nerd, Forensic Analyst, Author & Instructor of SANS FOR518
- @jaredcatkinson - PowerShell Forensics
- @maridegrazia - Computer Forensics Examiner
- @sleuthkit
- @williballenthin
- @XWaysGuide
-
-
Related Awesome Lists
-
Tools
Categories
Sub Categories
Other
19
Twitter
17
Windows Artifacts
13
Frameworks
11
Acquisition
10
Challenges
10
Distributions
9
OS X Forensics
8
Blogs
8
Memory Forensics
6
Disk image handling
6
Steganography
6
Mobile Forensics
6
Browser Artifacts
5
Carving
5
Live forensics
4
Timeline Analysis
4
Metadata Forensics
3
File System Corpora
3
Books
3
Imageing
3
Network Forensics
3
Docker Forensics
2
Picture Analysis
2
Website Forensics
2
Management
2
Decryption
2
Webs
1
Keywords
dfir
19
forensics
17
security
14
awesome
9
digital-forensics
9
incident-response
9
awesome-list
7
python
4
list
4
malware-analysis
4
cybersecurity
3
malware
3
memory-forensics
3
ioc
2
forensic-analysis
2
dynamic-analysis
2
ctf
2
malware-research
2
threat-hunting
2
static-analysis
2
ios
2
windows
2
android
2
ntfs
2
owasp
2
hacking
2
incident-response-tooling
2
incident-management
2
timeline
2
patch-management
1
reverse-engineering
1
microarchitecture
1
memory-hacking
1
memory-dump
1
memory-analysis
1
integrity-monitoring
1
hypervisor
1
cloud-computing
1
attestation
1
post-exploitation
1
inventory-management
1
apple
1
apfs-fuse
1
apfs
1
recover-files
1
partition
1
disk
1
visualization
1
python-3
1
javascript
1