Dissect is a digital forensics and incident response framework developed by Fox-IT, part of NCC Group. It provides a consistent interface for accessing forensic evidence even when the underlying disk images, file systems and operating systems differ substantially.
Rather than requiring an examiner to manually extract files from evidence containers, mount file systems and pass individual artefacts through separate utilities, Dissect abstracts many of these layers behind a common target model. Its command-line tools can therefore query forensic evidence directly while the framework handles the underlying formats.
The main Dissect repository acts as a meta package bringing together the compatible components of the wider modular framework.
This is free and open source software.
Key Features
- Provides target-query for querying parsed forensic artefacts.
- Offers target-shell for interactively navigating forensic targets.
- Works with evidence containers including E01, VMDK and QCoW images.
- Supports file systems including NTFS, ExtFS, APFS, Btrfs, FFS, XFS and VMFS.
- Parses Windows Registry data, Prefetch information, Event Logs and many other artefacts.
- Presents Windows, Linux and ESXi evidence through a common abstraction.
- Uses a modular architecture with reusable parsers and format implementations.
- Includes components for archives, databases, executable formats, encryption formats and volumes.
- Supports analysis of lightweight evidence containers created with Acquire.
- Reduces the need to manually extract and mount forensic evidence before analysis.
Website: github.com/fox-it/dissect
Support:
Developer: Dissect Team
License: GNU Affero General Public License v3.0
Dissect is written in Python. Learn Python with our recommended free books and free tutorials.
Related Software
| Network Analyzers | |
|---|---|
| Wireshark | Network protocol analyzer with a rich and powerful feature set |
| Sniffnet | Visualise live network traffic with a friendly interface |
| Kismet | Wireless network and device detector, sniffer, wardriving tool |
| Ettercap | Comprehensive suite for man in the middle attacks |
| IPTraf-ng | Feature-laden network statistic monitoring tool |
| Zeek | Network security monitoring with deep traffic insight |
| netsniff-ng | Swiss army knife for daily Linux network plumbing |
| Kyanos | Networking analysis tool using eBPF |
| Arkime | Indexes full packet captures for rapid, large-scale traffic investigation |
| EtherApe | Graphical network monitor |
| darkstat | Captures network traffic, calculates usage statistics, and serves reports |
| justniffer | Network TCP packet sniffer with reliable TCP flow rebuilding |
| tcpflow | TCP/IP packet demultiplexer |
| tcpdump | Powerful and hugely respected command-line packet analyzer |
| sniffglue | Packet sniffer written in Rust |
| sniffer | Alternative network traffic sniffer |
| RustNet | Terminal monitor for connections and bandwidth |
| Malcolm | Traffic analysis suite for capture, hunting and forensics |
| dsniff | Collection of tools for network auditing and penetration testing |
| ngrep | grep applied to the network layer |
| Network Monitor | Rreal-time network connection monitoring tool |
| sniffit | CORBA based sniffer system with ncurses interactive mode |
| Jomon | Network forensics and sniffer tool |
Read our verdict in the software roundup.
Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more. Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form. |


Please read our Comment Policy before commenting.