ForensicsTools
  
  
    A list of free and open forensics analysis tools and other resources 
    https://github.com/mesquidar/ForensicsTools
  
        Last synced: 1 day ago 
        JSON representation
    
- 
            
Collections
- DFIR-SQL-Query-Repo - Collection of SQL queries templates for digital forensics use by platform and application.
 - ForensicArtifacts.com Artifact Repository - Machine-readable knowledge base of forensic artifacts
 - DFIR – The definitive compendium project - Collection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more
 - dfir.training - Database of forensic resources focused on events, tools and more
 
 - 
            
Challenges
- 
                    
Distributions
- bitscout - LiveCD/LiveUSB for remote forensic acquisition and analysis
 - SANS Investigative Forensics Toolkit (sift) - Linux distribution for forensic analysis
 - CAINE
 - GRML-Forensic
 - Remnux - Distro for reverse-engineering and analyzing malicious software
 - Santoku Linux - Santoku is dedicated to mobile forensics, analysis, and security, and packaged in an easy to use, Open Source platform.
 - Sumuri Paladin - Linux distribution that simplifies various forensics tasks in a forensically sound manner via the PALADIN Toolbox
 - Tsurugi Linux - Linux distribution for forensic analysis
 - WinFE - Windows Forensics enviroment
 - Predator OS - Linux distribution for forensic analysis
 
 - 
                    
Frameworks
- dff - Forensic framework
 - dexter - Dexter is a forensics acquisition framework designed to be extensible and secure
 - IntelMQ - IntelMQ collects and processes security feeds
 - Kuiper - Digital Investigation Platform
 - Laika BOSS - Laika is an object scanner and intrusion detection system
 - RegRippy - is a framework for reading and extracting useful forensics data from Windows registry hives.
 - PowerForensics - PowerForensics is a framework for live disk forensic analysis
 - The Sleuth Kit - Tools for low level forensic analysis
 - turbinia - Turbinia is an open-source framework for deploying, managing, and running forensic workloads on cloud platforms
 - IPED - Indexador e Processador de Evidências Digitais - Brazilian Federal Police Tool for Forensic Investigations
 - Autopsy - SleuthKit GUI
 
 - 
                    
Live forensics
- grr - GRR Rapid Response: remote live forensics for incident response
 - Linux Expl0rer - Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask
 - mig - Distributed & real time digital forensics at the speed of the cloud
 - osquery - SQL powered operating system analytics
 
 - 
                    
Acquisition
- artifactcollector - A customizable agent to collect forensic artifacts on any Windows, macOS or Linux system
 - ArtifactExtractor - Extract common Windows artifacts from source images and VSCs
 - AVML - A portable volatile memory acquisition tool for Linux
 - FastIR Collector - Collect artifacts on windows
 - LiME - Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD
 - Velociraptor - Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries
 - RAM Capturer - by Belkasoft is a free tool to dump the data from a computer’s volatile memory. It’s compatible with Windows OS.
 - DFIR ORC - Forensics artefact collection tool for systems running Microsoft Windows
 - DumpIt
 - Magnet RAM Capture - is a free imaging tool designed to capture the physical memory
 
 - 
                    
Carving
- bstrings - Improved strings utility
 - bulk_extractor - Extracts informations like email adresses, creditscard numbers and histrograms of disk images
 - swap_digger - A bash script used to automate Linux swap analysis, automating swap extraction and searches for Linux user credentials, Web form credentials, Web form emails, etc.
 - photorec - File carving tool
 
 - 
                    
Memory Forensics
- inVtero.net - High speed memory analysis framework
 - KeeFarce - Extract KeePass passwords from memory
 - MemProcFS - An easy and convenient way of accessing physical memory as files a virtual file system.
 - Rekall - Memory Forensic Framework
 - volatility - The memory forensic framework
 - VolUtility - Web App for Volatility framework
 
 - 
                    
Network Forensics
 - 
                    
Windows Artifacts
- Beagle - Transform data sources and logs into graphs
 - LogonTracer - Investigate malicious Windows logon by visualizing and analyzing Windows event log
 - python-evt - Pure Python parser for classic Windows Event Log files (.evt)
 - RegRipper3.0 - RegRipper is an open source Perl tool for parsing the Registry and presenting it for analysis.
 - MFTExtractor - MFT-Parser
 - NTFS journal parser
 - NTFS USN Journal parser
 - RecuperaBit - Reconstruct and recover NTFS data
 - python-ntfs - NTFS analysis
 - LastActivityView - LastActivityView by Nirsoftis a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer.
 - MFT-Parsers - Comparison of MFT-Parsers
 - CrowdResponse - by CrowdStrike is a static host data collection tool
 - FRED - Cross-platform microsoft registry hive editor
 
 - 
                    
OS X Forensics
- APFS Fuse - is a read-only FUSE driver for the new Apple File System
 - APOLLO
 - mac_apt (macOS Artifact Parsing Tool) - Extracts forensic artifacts from disk images or live machines
 - MacLocationsScraper - Dump the contents of the location database files on iOS and macOS.
 - macMRUParser - Python script to parse the Most Recently Used (MRU) plist files on macOS into a more human friendly format.
 - OSXAuditor
 - OSX Collect
 - MAC OSX Artifacts - locations artifacts by mac4n6 group
 
 - 
                    
Mobile Forensics
- Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices
 - ALEAPP - An Android Logs Events and Protobuf Parser
 - iOS Frequent Locations Dumper - Dump the contents of the StateModel#.archive files located in /private/var/mobile/Library/Caches/com.apple.routined/
 - MEAT - Perform different kinds of acquisitions on iOS devices
 - MobSF - is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
 - OpenBackupExtractor - is an app for extracting data from iPhone and iPad backups.
 
 - 
                    
Docker Forensics
- dof (Docker Forensics Toolkit) - Extracts and interprets forensic artifacts from disk images of Docker Host systems
 - Docker Explorer
 
 - 
                    
Browser Artifacts
- chrome-url-dumper - Dump all local stored infromation collected by Chrome
 - hindsight - Internet history forensics for Google Chrome/Chromium
 - unfurl - Extract and visualize data from URLs
 - ChromeCacheView - by Nirsoft is a small utility that reads the cache folder of Google Chrome Web browser, and displays the list of all files currently stored in the cache
 - Dumpzilla - extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers
 
 - 
                    
Timeline Analysis
- DFTimewolf - Framework for orchestrating forensic collection, processing and data export using GRR and Rekall
 - plaso - Extract timestamps from various files and aggregate them
 - timeliner - A rewrite of mactime, a bodyfile reader
 - timesketch - Collaborative forensic timeline analysis
 
 - 
                    
Disk image handling
- Disk Arbitrator - A Mac OS X forensic utility designed to help the user ensure correct forensic procedures are followed during imaging of a disk device
 - imagemounter - Command line utility and Python package to ease the (un)mounting of forensic disk images
 - libewf - Libewf is a library and some tools to access the Expert Witness Compression Format (EWF, E01)
 - PancakeViewer - Disk image viewer based in dfvfs, similar to the FTK Imager viewer.
 - OSFMount - allows you to mount local disk image files (bit-for-bit copies of an entire disk or disk partition) in Windows as a physical disk or a logical drive
 - xmount - Convert between different disk image formats
 
 - 
                    
Management
 - 
                    
Picture Analysis
 - 
                    
Steganography
- Binwalk - Binwalk is a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images.
 - Foremost - is a program to recover files based on their headers and footers
 - Steghide - is a steganography program that hides data in various kinds of image and audio files
 - Wavsteg - is a steganography program that hides data in various kinds of image and audio files
 - Zsteg - A steganographic coder for WAV files
 - Stegsolve - analyze images in different planes by taking off bits of the image
 
 - 
                    
Metadata Forensics
 - 
                    
Imageing
- BelkaImager - by Belkasoft allows you to create images of hard and removable disks, Android and iOS devices and download data from the cloud.
 - dc3dd - Improved version of dd
 - Guymager - Open source version for disk imageing on linux systems
 
 - 
                    
Decryption
- hashcat - Fast password cracker with GPU support
 - John the Ripper - Password cracker
 
 
 - 
                    
 - 
            
Learn forensics
- 
                    
Challenges
 - 
                    
Website Forensics
- Forensic challenges - Mindmap of forensic challenges
 - OpenLearn - Digital forensic course
 
 
 - 
                    
 - 
            
Resources
- 
                    
Other
- ForensicPosters - Posters of file system structures
 - HFS+ Resources
 - mac4n6 Presentations - Presentation Archives for OS X and iOS Related Research
 - /r/computerforensics/ - Subreddit for computer forensics
 - ForensicControl
 
 - 
                    
Webs
 - 
                    
Blogs
 - 
                    
Books
- The Art of Memory Forensics - Detecting Malware and Threats in Windows, Linux, and Mac Memory
 - The Practice of Network Security Monitoring - Understanding Incident Detection and Response
 - Cell Phone Investigations: Search Warrants, Cell Sites and Evidence Recovery - Cell Phone Investigations is the most comprehensive book written on cell phones, cell sites, and cell related data.
 
 - 
                    
File System Corpora
- Digital Forensic Challenge Images - Two DFIR challenges with images
 - Digital Forensics Tool Testing Images
 - FAU Open Research Challenge Digital Forensics
 
 - 
                    
Twitter
- @4n6ist
 - @aheadless
 - @AppleExaminer - Apple OS X & iOS Digital Forensics
 - @blackbagtech
 - @carrier4n6 - Brian Carrier, author of Autopsy and the Sleuth Kit
 - @CindyMurph - Detective & Digital Forensic Examiner
 - @EricRZimmerman - Certified SANS Instructor
 - @forensikblog - Computer forensic geek
 - @HECFBlog - SANS Certified Instructor
 - @Hexacorn - DFIR+Malware
 - @hiddenillusion
 - @iamevltwin - Mac Nerd, Forensic Analyst, Author & Instructor of SANS FOR518
 - @jaredcatkinson - PowerShell Forensics
 - @maridegrazia - Computer Forensics Examiner
 - @sleuthkit
 - @williballenthin
 - @XWaysGuide
 
 
 - 
                    
 - 
            
Related Awesome Lists
 - 
            
Tools
 
            Categories
          
          
        
            Sub Categories
          
          
              
                Other
                17
              
              
                Twitter
                17
              
              
                Windows Artifacts
                13
              
              
                Frameworks
                11
              
              
                Acquisition
                10
              
              
                Distributions
                10
              
              
                Challenges
                10
              
              
                OS X Forensics
                8
              
              
                Blogs
                8
              
              
                Steganography
                6
              
              
                Mobile Forensics
                6
              
              
                Disk image handling
                6
              
              
                Memory Forensics
                6
              
              
                Browser Artifacts
                5
              
              
                Live forensics
                4
              
              
                Timeline Analysis
                4
              
              
                Carving
                4
              
              
                Metadata Forensics
                3
              
              
                File System Corpora
                3
              
              
                Books
                3
              
              
                Imageing
                3
              
              
                Network Forensics
                3
              
              
                Docker Forensics
                2
              
              
                Picture Analysis
                2
              
              
                Website Forensics
                2
              
              
                Management
                2
              
              
                Decryption
                2
              
              
                Webs
                1
              
          
        
            Keywords
          
          
              
                dfir
                19
              
              
                forensics
                17
              
              
                security
                14
              
              
                digital-forensics
                9
              
              
                incident-response
                9
              
              
                awesome
                9
              
              
                awesome-list
                7
              
              
                python
                4
              
              
                list
                4
              
              
                memory-forensics
                3
              
              
                malware-analysis
                3
              
              
                cybersecurity
                3
              
              
                forensic-analysis
                2
              
              
                malware-research
                2
              
              
                malware
                2
              
              
                ioc
                2
              
              
                incident-management
                2
              
              
                incident-response-tooling
                2
              
              
                threat-hunting
                2
              
              
                dynamic-analysis
                2
              
              
                ctf
                2
              
              
                hacking
                2
              
              
                owasp
                2
              
              
                windows
                2
              
              
                ios
                2
              
              
                ntfs
                2
              
              
                android
                2
              
              
                static-analysis
                2
              
              
                timeline
                2
              
              
                patch-management
                1
              
              
                reverse-engineering
                1
              
              
                secure-hash
                1
              
              
                microarchitecture
                1
              
              
                memory-hacking
                1
              
              
                memory-dump
                1
              
              
                memory-analysis
                1
              
              
                integrity-monitoring
                1
              
              
                hypervisor
                1
              
              
                cloud-computing
                1
              
              
                attestation
                1
              
              
                post-exploitation
                1
              
              
                inventory-management
                1
              
              
                driver
                1
              
              
                apple
                1
              
              
                apfs-fuse
                1
              
              
                apfs
                1
              
              
                recover-files
                1
              
              
                partition
                1
              
              
                disk
                1
              
              
                visualization
                1