Awesome Lists

awesome-forensics

by cugu

awesome listpushed almost 2 years ago

⭐️ A curated list of awesome forensic analysis tools and resources

AI summary

Forensic toolkit

A curated collection of tools and resources for forensic analysis and digital forensics

stars
4K
forks
630
watching
175
awesome lists
10
entries
180
View on GitHubcugu.github.io/awesome-forensics

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/cugu/awesome-forensics/links.svg)](https://awesome.facts.dev/awesome/cugu/awesome-forensics)
HTML
<a href="https://awesome.facts.dev/awesome/cugu/awesome-forensics"><img src="https://awesome.facts.dev/shield/cugu/awesome-forensics/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/cugu/awesome-forensics/links.svg

What's in the list

180 links in 33 sections, with live GitHub stats.activeno commit in 2y

Collections

Tools

Tools / Distributions

Tools / Frameworks

  • Autopsy

    SleuthKit GUI

  • dexter

    Dexter is a forensics acquisition framework designed to be extensible and secure

  • dff

    Forensic framework

  • Dissect

    Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group)

  • hashlookup-forensic-analyser

    A tool to analyse files from a forensic acquisition to find known/unknown hashes from API or using a local Bloom filter

  • IntelMQ

    IntelMQ collects and processes security feeds

  • Kuiper

    Digital Investigation Platform

  • Laika BOSS

    Laika is an object scanner and intrusion detection system

  • OpenRelik

    Forensic platform to store file artifacts and run workflows

  • PowerForensics

    PowerForensics is a framework for live disk forensic analysis

  • TAPIR

    TAPIR (Trustable Artifacts Parser for Incident Response) is a multi-user, client/server, incident response framework

  • The Sleuth Kit

    Tools for low level forensic analysis

  • turbinia

    Turbinia is an open-source framework for deploying, managing, and running forensic workloads on cloud platforms

  • IPED - Indexador e Processador de Evidências Digitais

    Brazilian Federal Police Tool for Forensic Investigations

  • Wombat Forensics

    Forensic GUI tool

Tools / Live Forensics

  • grr

    GRR Rapid Response: remote live forensics for incident response

  • Linux Expl0rer

    Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask

  • mig

    Distributed & real time digital forensics at the speed of the cloud

  • osquery

    SQL powered operating system analytics

  • POFR

    The Penguin OS Flight Recorder collects, stores and organizes for further analysis process execution, file access and network/socket endpoint data from the Linux Operating System

  • UAC

    UAC (Unix-like Artifacts Collector) is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts

Tools / IOC Scanner

  • Fastfinder

    Fast customisable cross-platform suspicious file finder. Supports md5/sha1/sha256 hashes, literal/wildcard strings, regular expressions and YARA rules

  • Fenrir

    Simple Bash IOC Scanner

  • Loki

    Simple IOC and Incident Response Scanner

  • Redline

    Free endpoint security tool from FireEye

  • THOR Lite

    Free IOC and YARA Scanner

  • recon

    Performance oriented file finder with support for SQL querying, index and analyze file metadata with support for YARA

Tools / Acquisition

  • Acquire

    Acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container

  • artifactcollector

    A customizable agent to collect forensic artifacts on any Windows, macOS or Linux system

  • ArtifactExtractor

    Extract common Windows artifacts from source images and VSCs

  • AVML

    A portable volatile memory acquisition tool for Linux

  • Belkasoft RAM Capturer

    Volatile Memory Acquisition Tool

  • DFIR ORC

    Forensics artefact collection tool for systems running Microsoft Windows

  • FastIR Collector

    Collect artifacts on windows

  • FireEye Memoryze

    A free memory forensic software

  • FIT

    Forensic acquisition of web pages, emails, social media, etc

  • ForensicMiner

    A PowerShell-based DFIR automation tool, for artifact and evidence collection on Windows machines

  • LiME

    Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD

  • Magnet RAM Capture / DumpIt

    A free imaging tool designed to capture the physical memory

  • SPECTR3

    Acquire, triage and investigate remote evidence via portable iSCSI readonly access

  • UFADE

    Extract files from iOS devices on Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates iTunes-style backups and advanced logical backups

  • unix_collector

    A live forensic collection script for UNIX-like systems as a single script

  • Velociraptor

    Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries

  • WinTriage

    Wintriage is a live response tool that extracts Windows artifacts. It must be executed with local or domain administrator privileges and recommended to be done from an external drive

Tools / Imaging

  • dc3dd

    Improved version of dd

  • dcfldd

    Different improved version of dd (this version has some bugs!, another version is on github )

  • FTK Imager

    Free imageing tool for windows

  • Guymager

    Open source version for disk imageing on linux systems

  • 4n6pi

    Forensic disk imager, designed to run on a Raspberry Pi, powered by libewf

Tools / Carving

  • bstrings

    Improved strings utility

  • bulk_extractor

    Extracts information such as email addresses, creditcard numbers and histrograms from disk images

  • floss

    Static analysis tool to automatically deobfuscate strings from malware binaries

  • photorec

    File carving tool

  • swap_digger

    A bash script used to automate Linux swap analysis, automating swap extraction and searches for Linux user credentials, Web form credentials, Web form emails, etc

Tools / Memory Forensics

  • inVtero.net

    High speed memory analysis framework developed in .NET supports all Windows x64, includes code integrity and write support

  • KeeFarce

    Extract KeePass passwords from memory

  • MemProcFS

    An easy and convenient way of accessing physical memory as files a virtual file system

  • Rekall

    Memory Forensic Framework

  • volatility

    The memory forensic framework

  • VolUtility

    Web App for Volatility framework

Tools / Network Forensics

  • Kismet

    A passive wireless sniffer

  • NetworkMiner

    Network Forensic Analysis Tool

  • Squey

    Logs/PCAP visualization software designed to detect anomalies and weak signals in large amounts of data

  • WireShark

    A network protocol analyzer

Tools / Windows Artifacts

  • Beagle

    Transform data sources and logs into graphs

  • Blauhaunt

    A tool collection for filtering and visualizing logon events

  • FRED

    Cross-platform microsoft registry hive editor

  • Hayabusa

    A a sigma-based threat hunting and fast forensics timeline generator for Windows event logs

  • LastActivityView

    LastActivityView by Nirsoftis a tool for Windows operating system that collects information from various sources on a running system, and displays a log of actions made by the user and events occurred on this computer

  • LogonTracer

    Investigate malicious Windows logon by visualizing and analyzing Windows event log

  • PyShadow

    A library for Windows to read shadow copies, delete shadow copies, create symbolic links to shadow copies, and create shadow copies

  • python-evt

    Pure Python parser for classic Windows Event Log files (.evt)

  • RegRipper3.0

    RegRipper is an open source Perl tool for parsing the Registry and presenting it for analysis

  • RegRippy

    A framework for reading and extracting useful forensics data from Windows registry hives

  • MFT-Parsers

    Comparison of MFT-Parsers

  • MFTEcmd

    MFT Parser by Eric Zimmerman

  • MFTExtractor

    MFT-Parser

  • MFTMactime

    MFT and USN parser that allows direct extraction in filesystem timeline format (mactime), dump all resident files in the MFT in their original folder structure and run yara rules over them all

  • RecuperaBit

    Reconstruct and recover NTFS data

  • python-ntfs

    NTFS analysis

Tools / OS X Forensics

Tools / Mobile Forensics

  • Andriller

    A software utility with a collection of forensic tools for smartphones

  • ALEAPP

    An Android Logs Events and Protobuf Parser

  • ArtEx

    Artifact Examiner for iOS Full File System extractions

  • iLEAPP

    An iOS Logs, Events, And Plists Parser

  • iOS Frequent Locations Dumper

    Dump the contents of the StateModel#.archive files located in /private/var/mobile/Library/Caches/com.apple.routined/

  • MEAT

    Perform different kinds of acquisitions on iOS devices

  • MobSF

    An automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis

  • OpenBackupExtractor

    An app for extracting data from iPhone and iPad backups

Tools / Docker Forensics

  • dof (Docker Forensics Toolkit)

    Extracts and interprets forensic artifacts from disk images of Docker Host systems

  • Docker Explorer

    Extracts and interprets forensic artifacts from disk images of Docker Host systems

Tools / Internet Artifacts

  • ChromeCacheView

    A small utility that reads the cache folder of Google Chrome Web browser, and displays the list of all files currently stored in the cache

  • chrome-url-dumper

    Dump all local stored infromation collected by Chrome

  • hindsight

    Internet history forensics for Google Chrome/Chromium

  • IE10Analyzer

    This tool can parse normal records and recover deleted records in WebCacheV01.dat

  • unfurl

    Extract and visualize data from URLs

  • WinSearchDBAnalyzer

    This tool can parse normal records and recover deleted records in Windows.edb

Tools / Timeline Analysis

  • DFTimewolf

    Framework for orchestrating forensic collection, processing and data export using GRR and Rekall

  • plaso

    Extract timestamps from various files and aggregate them

  • Timeline Explorer

    Timeline Analysis tool for CSV and Excel files. Built for SANS FOR508 students

  • timeliner

    A rewrite of mactime, a bodyfile reader

  • timesketch

    Collaborative forensic timeline analysis

Tools / Disk image handling

  • Disk Arbitrator

    A Mac OS X forensic utility designed to help the user ensure correct forensic procedures are followed during imaging of a disk device

  • imagemounter

    Command line utility and Python package to ease the (un)mounting of forensic disk images

  • libewf

    Libewf is a library and some tools to access the Expert Witness Compression Format (EWF, E01)

  • PancakeViewer

    Disk image viewer based in dfvfs, similar to the FTK Imager viewer

  • xmount

    Convert between different disk image formats

Tools / Decryption

Tools / Management

  • Catalyst

    Catalyst is an open source security automation and ticket system

  • dfirtrack

    Digital Forensics and Incident Response Tracking application, track systems

  • Incidents

    Web application for organizing non-trivial security investigations. Built on the idea that incidents are trees of tickets, where some tickets are leads

  • iris

    Collaborative Incident Response platform

Tools / Picture Analysis

  • Ghiro

    A fully automated tool designed to run forensics analysis over a massive amount of images

  • sherloq

    An open-source digital photographic image forensic toolset

Tools / Metadata Forensics

  • ExifTool

    by Phil Harvey

  • FOCA

    FOCA is a tool used mainly to find metadata and hidden information in the documents

Tools / Steganography

  • Steghide

    is a steganography program that hides data in various kinds of image and audio files

  • Wavsteg

    is a steganography program that hides data in various kinds of image and audio files

  • Zsteg

    A steganographic coder for WAV files

Learn Forensics

Learn Forensics / CTFs and Challenges

Resources / Web

Resources / Blogs

Resources / Books

Resources / File System Corpora

Resources / File System Corpora / The CFReDS Project

Resources / Other

Resources / Labs

  • BlueTeam.Lab

    Blue Team detection lab created with Terraform and Ansible in Azure

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.