awesome-forensics

Forensic toolkit

A curated collection of tools and resources for forensic analysis and digital forensics

⭐️ A curated list of awesome forensic analysis tools and resources

GitHub

4k stars
175 watching
630 forks
last commit: almost 2 years ago
Linked from 10 awesome lists

computer-forensicsdfirdigital-forensicsforensic-analysisfreeopen-source

Awesome Forensics / Collections

AboutDFIR – The Definitive Compendium ProjectCollection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more
ForensicArtifacts.com Artifact Repository1,071about 2 years agoMachine-readable knowledge base of forensic artifacts

Awesome Forensics / Tools

Forensics tools on Wikipedia
Eric Zimmerman's Tools

Awesome Forensics / Tools / Distributions

bitscout464over 2 years agoLiveCD/LiveUSB for remote forensic acquisition and analysis
RemnuxDistro for reverse-engineering and analyzing malicious software
SANS Investigative Forensics Toolkit (sift)494over 2 years agoLinux distribution for forensic analysis
Tsurugi LinuxLinux distribution for forensic analysis
WinFEWindows Forensics enviroment

Awesome Forensics / Tools / Frameworks

AutopsySleuthKit GUI
dexter126over 7 years agoDexter is a forensics acquisition framework designed to be extensible and secure
dff276over 6 years agoForensic framework
Dissect939almost 2 years agoDissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group)
hashlookup-forensic-analyser126about 3 years agoA tool to analyse files from a forensic acquisition to find known/unknown hashes from API or using a local Bloom filter
IntelMQ985almost 2 years agoIntelMQ collects and processes security feeds
Kuiper777almost 2 years agoDigital Investigation Platform
Laika BOSS743almost 2 years agoLaika is an object scanner and intrusion detection system
OpenRelikForensic platform to store file artifacts and run workflows
PowerForensics1,389almost 3 years agoPowerForensics is a framework for live disk forensic analysis
TAPIR45about 4 years agoTAPIR (Trustable Artifacts Parser for Incident Response) is a multi-user, client/server, incident response framework
The Sleuth Kit2,648almost 2 years agoTools for low level forensic analysis
turbinia754almost 2 years agoTurbinia is an open-source framework for deploying, managing, and running forensic workloads on cloud platforms
IPED - Indexador e Processador de Evidências Digitais996almost 2 years agoBrazilian Federal Police Tool for Forensic Investigations
Wombat Forensics48about 2 years agoForensic GUI tool

Awesome Forensics / Tools / Live Forensics

grr4,811almost 2 years agoGRR Rapid Response: remote live forensics for incident response
Linux Expl0rer407over 2 years agoEasy-to-use live forensics toolbox for Linux endpoints written in Python & Flask
mig1,205about 7 years agoDistributed & real time digital forensics at the speed of the cloud
osquery22,065almost 2 years agoSQL powered operating system analytics
POFR38about 2 years agoThe Penguin OS Flight Recorder collects, stores and organizes for further analysis process execution, file access and network/socket endpoint data from the Linux Operating System
UAC824almost 2 years agoUAC (Unix-like Artifacts Collector) is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts

Awesome Forensics / Tools / IOC Scanner

Fastfinder234over 4 years agoFast customisable cross-platform suspicious file finder. Supports md5/sha1/sha256 hashes, literal/wildcard strings, regular expressions and YARA rules
Fenrir702over 4 years agoSimple Bash IOC Scanner
Loki3,419almost 2 years agoSimple IOC and Incident Response Scanner
RedlineFree endpoint security tool from FireEye
THOR LiteFree IOC and YARA Scanner
recon32almost 4 years agoPerformance oriented file finder with support for SQL querying, index and analyze file metadata with support for YARA

Awesome Forensics / Tools / Acquisition

Acquire92almost 2 years agoAcquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container
artifactcollector271almost 2 years agoA customizable agent to collect forensic artifacts on any Windows, macOS or Linux system
ArtifactExtractor66over 5 years agoExtract common Windows artifacts from source images and VSCs
AVML883almost 2 years agoA portable volatile memory acquisition tool for Linux
Belkasoft RAM CapturerVolatile Memory Acquisition Tool
DFIR ORCForensics artefact collection tool for systems running Microsoft Windows
FastIR Collector507over 5 years agoCollect artifacts on windows
FireEye MemoryzeA free memory forensic software
FIT71almost 2 years agoForensic acquisition of web pages, emails, social media, etc
ForensicMiner149over 2 years agoA PowerShell-based DFIR automation tool, for artifact and evidence collection on Windows machines
LiME1,739almost 2 years agoLoadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD
Magnet RAM Capture / DumpItA free imaging tool designed to capture the physical memory
SPECTR339almost 2 years agoAcquire, triage and investigate remote evidence via portable iSCSI readonly access
UFADE175almost 2 years agoExtract files from iOS devices on Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates iTunes-style backups and advanced logical backups
unix_collector33almost 2 years agoA live forensic collection script for UNIX-like systems as a single script
Velociraptor3,020almost 2 years agoVelociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries
WinTriageWintriage is a live response tool that extracts Windows artifacts. It must be executed with local or domain administrator privileges and recommended to be done from an external drive

Awesome Forensics / Tools / Imaging

dc3ddImproved version of dd
dcflddDifferent improved version of dd (this version has some bugs!, another version is on github )
FTK ImagerFree imageing tool for windows
GuymagerOpen source version for disk imageing on linux systems
4n6pi18about 2 years agoForensic disk imager, designed to run on a Raspberry Pi, powered by libewf

Awesome Forensics / Tools / Carving

bstrings121about 3 years agoImproved strings utility
bulk_extractor1,129almost 2 years agoExtracts information such as email addresses, creditcard numbers and histrograms from disk images
floss3,337almost 2 years agoStatic analysis tool to automatically deobfuscate strings from malware binaries
photorecFile carving tool
swap_digger515over 5 years agoA bash script used to automate Linux swap analysis, automating swap extraction and searches for Linux user credentials, Web form credentials, Web form emails, etc

Awesome Forensics / Tools / Memory Forensics

inVtero.net281almost 3 years agoHigh speed memory analysis framework developed in .NET supports all Windows x64, includes code integrity and write support
KeeFarce1,002almost 11 years agoExtract KeePass passwords from memory
MemProcFS3,215almost 2 years agoAn easy and convenient way of accessing physical memory as files a virtual file system
Rekall1,931almost 6 years agoMemory Forensic Framework
volatility7,412over 3 years agoThe memory forensic framework
VolUtility381almost 2 years agoWeb App for Volatility framework

Awesome Forensics / Tools / Network Forensics

Kismet1,631almost 2 years agoA passive wireless sniffer
NetworkMinerNetwork Forensic Analysis Tool
SqueyLogs/PCAP visualization software designed to detect anomalies and weak signals in large amounts of data
WireSharkA network protocol analyzer

Awesome Forensics / Tools / Windows Artifacts

Beagle1,275almost 4 years agoTransform data sources and logs into graphs
Blauhaunt164almost 2 years agoA tool collection for filtering and visualizing logon events
FREDCross-platform microsoft registry hive editor
Hayabusa2,353almost 2 years agoA a sigma-based threat hunting and fast forensics timeline generator for Windows event logs
LastActivityViewLastActivityView by Nirsoftis a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer
LogonTracer2,756over 2 years agoInvestigate malicious Windows logon by visualizing and analyzing Windows event log
PyShadow6about 2 years agoA library for Windows to read shadow copies, delete shadow copies, create symbolic links to shadow copies, and create shadow copies
python-evt49about 3 years agoPure Python parser for classic Windows Event Log files (.evt)
RegRipper3.0562almost 2 years agoRegRipper is an open source Perl tool for parsing the Registry and presenting it for analysis
RegRippy188almost 2 years agoA framework for reading and extracting useful forensics data from Windows registry hives
MFT-ParsersComparison of MFT-Parsers
MFTEcmdMFT Parser by Eric Zimmerman
MFTExtractor14almost 2 years agoMFT-Parser
MFTMactime12over 3 years agoMFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all
NTFS journal parser
NTFS USN Journal parser108about 4 years ago
RecuperaBit549over 2 years agoReconstruct and recover NTFS data
python-ntfs81almost 9 years agoNTFS analysis

Awesome Forensics / Tools / OS X Forensics

APFS Fuse1,814about 2 years agoA read-only FUSE driver for the new Apple File System
mac_apt (macOS Artifact Parsing Tool)790almost 2 years agoExtracts forensic artifacts from disk images or live machines
MacLocationsScraper79almost 4 years agoDump the contents of the location database files on iOS and macOS
macMRUParser101over 8 years agoPython script to parse the Most Recently Used (MRU) plist files on macOS into a more human friendly format
OSXAuditor3,128about 6 years ago
OSX Collect1,879over 7 years ago

Awesome Forensics / Tools / Mobile Forensics

Andriller1,356about 4 years agoA software utility with a collection of forensic tools for smartphones
ALEAPP536almost 2 years agoAn Android Logs Events and Protobuf Parser
ArtExArtifact Examiner for iOS Full File System extractions
iLEAPP767almost 2 years agoAn iOS Logs, Events, And Plists Parser
iOS Frequent Locations Dumper82almost 8 years agoDump the contents of the StateModel#.archive files located in /private/var/mobile/Library/Caches/com.apple.routined/
MEAT140over 6 years agoPerform different kinds of acquisitions on iOS devices
MobSF17,691almost 2 years agoAn automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis
OpenBackupExtractor162over 4 years agoAn app for extracting data from iPhone and iPad backups

Awesome Forensics / Tools / Docker Forensics

dof (Docker Forensics Toolkit)95over 2 years agoExtracts and interprets forensic artifacts from disk images of Docker Host systems
Docker Explorer531almost 2 years agoExtracts and interprets forensic artifacts from disk images of Docker Host systems

Awesome Forensics / Tools / Internet Artifacts

ChromeCacheViewA small utility that reads the cache folder of Google Chrome Web browser, and displays the list of all files currently stored in the cache
chrome-url-dumper34almost 9 years agoDump all local stored infromation collected by Chrome
hindsight1,097almost 2 years agoInternet history forensics for Google Chrome/Chromium
IE10Analyzer15about 2 years agoThis tool can parse normal records and recover deleted records in WebCacheV01.dat
unfurl619almost 2 years agoExtract and visualize data from URLs
WinSearchDBAnalyzer121about 2 years agoThis tool can parse normal records and recover deleted records in Windows.edb

Awesome Forensics / Tools / Timeline Analysis

DFTimewolf299almost 2 years agoFramework for orchestrating forensic collection, processing and data export using GRR and Rekall
plaso1,745almost 2 years agoExtract timestamps from various files and aggregate them
Timeline ExplorerTimeline Analysis tool for CSV and Excel files. Built for SANS FOR508 students
timeliner37about 2 years agoA rewrite of mactime, a bodyfile reader
timesketch2,641almost 2 years agoCollaborative forensic timeline analysis

Awesome Forensics / Tools / Disk image handling

Disk Arbitrator666over 2 years agoA Mac OS X forensic utility designed to help the user ensure correct forensic procedures are followed during imaging of a disk device
imagemounter121over 3 years agoCommand line utility and Python package to ease the (un)mounting of forensic disk images
libewf270about 2 years agoLibewf is a library and some tools to access the Expert Witness Compression Format (EWF, E01)
PancakeViewer40over 6 years agoDisk image viewer based in dfvfs, similar to the FTK Imager viewer
xmountConvert between different disk image formats

Awesome Forensics / Tools / Decryption

hashcatFast password cracker with GPU support
John the RipperPassword cracker

Awesome Forensics / Tools / Management

Catalyst361almost 2 years agoCatalyst is an open source security automation and ticket system
dfirtrack482about 2 years agoDigital Forensics and Incident Response Tracking application, track systems
Incidents65over 3 years agoWeb application for organizing non-trivial security investigations. Built on the idea that incidents are trees of tickets, where some tickets are leads
iris1,091almost 2 years agoCollaborative Incident Response platform

Awesome Forensics / Tools / Picture Analysis

Ghiro486about 10 years agoA fully automated tool designed to run forensics analysis over a massive amount of images
sherloq2,681almost 2 years agoAn open-source digital photographic image forensic toolset

Awesome Forensics / Tools / Metadata Forensics

ExifToolby Phil Harvey
FOCA3,016almost 4 years agoFOCA is a tool used mainly to find metadata and hidden information in the documents

Awesome Forensics / Tools / Steganography

Sonicvisualizer
Steghide601over 2 years agois a steganography program that hides data in various kinds of image and audio files
Wavsteg14almost 9 years agois a steganography program that hides data in various kinds of image and audio files
Zsteg1,333over 2 years agoA steganographic coder for WAV files

Awesome Forensics / Learn Forensics

Forensic challengesMindmap of forensic challenges
OpenLearnDigital forensic course

Awesome Forensics / Learn Forensics / CTFs and Challenges

BelkaCTFCTFs by Belkasoft
CyberDefenders
DefCon CTFsarchive of DEF CON CTF challenges
Forensics CTFs9,929about 2 years ago
MagnetForensics CTF Challenge
MalwareTech Challenges
MemLabs1,670over 5 years ago
NW3C Chanllenges
Precision Widgets of North Dakota Intrusion
ReverseEngineering Challenges

Awesome Forensics / Resources / Web

ForensicsFocus
Insecstitute Resources
SANS Digital Forensics

Awesome Forensics / Resources / Blogs

Netresec
SANS Forensics Blog
SecurityAffairsblog by Pierluigi Paganini
This Week In 4n6Weekly updates for forensics
Zena Forensics

Awesome Forensics / Resources / Books

Network Forensics: Tracking Hackers through CyberspaceLearn to recognize hackers’ tracks and uncover network-based evidence
The Art of Memory ForensicsDetecting Malware and Threats in Windows, Linux, and Mac Memory
The Practice of Network Security MonitoringUnderstanding Incident Detection and Response

Awesome Forensics / Resources / File System Corpora

Digital Forensic Challenge ImagesTwo DFIR challenges with images
Digital Forensics Tool Testing Images
The CFReDS Project

Awesome Forensics / Resources / File System Corpora / The CFReDS Project

Hacking Case (4.5 GB NTFS Image)

Awesome Forensics / Resources / Other

/r/computerforensics/Subreddit for computer forensics
ForensicPosters437almost 2 years agoPosters of file system structures
SANS PostersFree posters provided by SANS

Awesome Forensics / Resources / Labs

BlueTeam.Lab143almost 2 years agoBlue Team detection lab created with Terraform and Ansible in Azure
Android Security8,270almost 2 years ago
AppSec6,372about 2 years ago
CTFs9,929about 2 years ago
Hacking13,321over 2 years ago
Honeypots8,732about 2 years ago
Incident-Response7,728about 2 years ago
Infosec5,221over 2 years ago
Malware Analysis12,073over 2 years ago
Pentesting22,116almost 2 years ago
Security12,563about 2 years ago
Social Engineering2,755over 3 years ago
YARA3,598almost 2 years ago

Backlinks from these awesome lists:

More related projects: