wiki:tools:start
Table of Contents
Forensic Tools
Definition
This directory collects the forensic tools, parsers, acquisition utilities, timeline systems, malware-analysis environments, cloud helpers, and native references used across the wiki. A tool can parse evidence, organize evidence, and sometimes rescue evidence from cold sectors. It still cannot understand the case for you.
Tool Categories
Core
- Autopsy - Case review, file-system browsing, timelines, term search, and recovered artifact review.
- The Sleuth Kit - Command-line file-system analysis and evidence inspection.
- FTK Imager - Forensic imaging, preview, and export workflows.
- Guymager - Linux forensic imaging with hashing and acquisition logs.
- dc3dd - Disk imaging and hashing utility.
- GNU ddrescue - Imaging damaged media while preserving recovery logs.
- Arsenal Image Mounter - Mount forensic images for controlled review.
- Magnet AXIOM - Commercial forensic suite for computer, mobile, and cloud evidence review.
- Belkasoft X - Commercial forensic suite for computers, mobile devices, and cloud artifacts.
- X-Ways Forensics - Commercial forensic suite for file systems, carving, and case analysis.
- OSForensics - Host artifact review and case analysis suite.
- ExifTool - Metadata extraction across images, documents, and many file formats.
- bulk_extractor - Feature extraction from disk images without relying on file-system allocation.
- PhotoRec and TestDisk - File recovery and partition recovery utilities.
- Foremost - File carving by headers, footers, and simple signatures.
- Scalpel - Configurable file carving utility.
- hashdeep - Recursive hashing, audit, and hash-set comparison.
- dfVFS - Virtual file-system abstraction used by forensic tools.
- libewf - Expert Witness Format image support library.
- libvshadow - Volume Shadow Copy parsing library.
- libfsntfs - NTFS file-system parsing library.
Timeline
- Plaso - Timeline extraction and normalization across many artifact types.
- Timesketch - Collaborative timeline analysis and event tagging.
- dfDateTime - Timestamp conversion and interpretation support.
- CyberChef - Timestamp conversion, decoding, and quick data transformations.
- jq - JSON parsing for logs, exports, and cloud evidence.
- yq - YAML, JSON, XML, and properties parsing during evidence review.
Windows
- Eric Zimmerman's Tools - Windows artifact parsers including MFTECmd, PECmd, EvtxECmd, and others.
- KAPE - Targeted artifact collection and processing.
- Sysinternals Suite - Microsoft Windows internals and triage tools.
- Autoruns - Persistence and autorun location review.
- Process Monitor - Process, registry, and file activity observation.
- Sysmon - High-fidelity Windows endpoint telemetry.
- RegRipper - Registry parsing framework and plugins.
- Hayabusa - Windows event log hunting and timeline support.
- Chainsaw - Windows event log search and detection.
- Zircolite - Sigma-based event log scanning.
- Event Log Explorer - Windows event log viewing and filtering.
- PowerShell - Native Windows automation and log review context.
- EVTXtract - Carving and recovering EVTX event log fragments.
- ProcDump - Process dump collection for troubleshooting and memory review.
- TCPView - Windows network connection visibility.
- PowerForensics - PowerShell forensic artifact access and parsing.
- Kansa - PowerShell-based incident response collection framework.
- dfWinReg - Windows Registry parsing support library.
Linux Macos
- osquery - Structured endpoint state collection across operating systems.
- SIFT Workstation - DFIR workstation distribution and toolset.
- mac_apt - macOS artifact parsing and reporting.
- APOLLO - SQLite query framework for Apple artifacts.
- libyal - Forensic libraries for many evidence formats.
- Velociraptor - Endpoint collection, hunting, and artifact triage.
Browser Mobile Cloud
- DB Browser for SQLite - Manual SQLite database review for browser and app artifacts.
- SQLite - Reference documentation for SQLite databases used by many applications.
- Browser History Capturer - Browser history acquisition support.
- Browser History Examiner - Browser artifact review support.
- ADB Platform Tools - Android device communication and collection support.
- libimobiledevice - Open tooling for iOS device interactions.
- iLEAPP - iOS artifact parsing and report generation.
- ALEAPP - Android artifact parsing and report generation.
- Mobile Verification Toolkit - Mobile compromise indicator checks and extraction support.
- Cellebrite UFED - Commercial mobile device extraction platform.
- Oxygen Forensic Detective - Commercial mobile and cloud forensic suite.
- MSAB XRY - Commercial mobile extraction and analysis platform.
- Elcomsoft Phone Breaker - Mobile and cloud acquisition support where authorized.
- MobSF - Mobile application security and artifact analysis framework.
- jadx - Android APK decompiler for application review.
- Apktool - Android APK reverse engineering and resource inspection.
- Frida - Dynamic instrumentation framework for authorized app and malware analysis.
- Rclone - Cloud storage listing and collection support where authorized.
- Microsoft Graph PowerShell - Microsoft cloud audit and account data access where authorized.
Network Ir
- Wireshark - Packet capture and protocol review.
- Zeek - Network security monitoring logs.
- Suricata - Network detection and packet inspection.
- NetworkMiner - Network forensic artifact extraction.
- Arkime - Full-packet capture indexing and search.
- GRR Rapid Response - Remote live response and collection.
- DFIR ORC - Enterprise-scale Windows collection.
- Dissect - Forensic parsing framework for disks, images, and host artifacts.
- Wazuh - Endpoint security monitoring and alert context.
- MISP - Threat intelligence and indicator sharing platform.
- TheHive - Incident response case management platform.
Memory Malware
- Volatility 3 - Memory analysis and plugin-driven investigation.
- WinPmem - Windows memory acquisition.
- LiME - Linux memory acquisition.
- AVML - Linux memory acquisition for cloud and endpoint response.
- MemProcFS - Memory analysis through a virtual file-system interface.
- REMnux - Linux malware analysis environment.
- FLARE-VM - Windows malware analysis toolkit.
- Ghidra - Reverse engineering suite.
- radare2 - Reverse engineering framework.
- x64dbg - Windows debugger for malware analysis.
- YARA - Pattern matching for malware triage.
- capa - Capability detection for executable analysis.
- FLOSS - String decoding and extraction for malware analysis.
- Detect It Easy - File type, compiler, and packer identification.
- oletools - Microsoft Office document analysis utilities.
- pefile - Portable Executable parsing.
- LIEF - Executable format parsing and instrumentation.
- dnSpyEx - .NET assembly inspection and debugging.
- CAPE Sandbox - Malware sandbox analysis platform.
- MobSF - Mobile application security and artifact analysis framework.
- jadx - Android APK decompiler for application review.
- Apktool - Android APK reverse engineering and resource inspection.
- Frida - Dynamic instrumentation framework for authorized app and malware analysis.
- Sigma - Detection rule format for investigative hunting.
Privacy Encryption
- VeraCrypt - Reference point for encrypted container behavior.
- 7-Zip - Archive and encryption utility often encountered in cases.
- KeePass - Password manager reference point.
- Cryptomator - Client-side encrypted storage reference point.
- Tor Browser - Reference point for privacy-browser artifacts.
- Tails - Privacy-focused operating system reference point.
Project Resources
Use Notes
This article is for defensive education and technical reference. It should not be treated as legal, forensic, investigative, compliance, or operational advice without qualified professional judgment.
wiki/tools/start.txt · Last modified: by 127.0.0.1
