Digital forensics is a specialist art. It allows investigations to be undertaken without modifying the media.
Read more
Digital forensics is a specialist art. It allows investigations to be undertaken without modifying the media.
Read more
Volshell is a utility to access the volatility framework interactively with a specific memory image.
Read more
pypykatz is a cross-platform implementation of Mimikatz written in Python.
Read more
MemProcFS is an easy and convenient way of viewing physical memory as files in a virtual file system.
Read more
EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.
Read more
iaito is the official graphical interface for radare2, a libre reverse engineering framework.
Read more
Jomon is a network forensics and passive sniffer tool. It monitors all incoming/outgoing network traffic, without the use of libpcap
Read more
GRR Rapid Response is an incident response framework focused on remote live forensics.
Read more
MIG is a platform to perform investigative surgery on remote endpoints. It enables investigators to obtain information from large numbers of systems in parallel.
Read more
The Sleuth Kit (TSK) is a library and collection of command line file and volume system forensic analysis tools.
Read more
The Autopsy Forensic Browser is a graphical interface to the command line digital investigation tools in The Sleuth Kit.
Read more
The Volatility Framework is a completely open collection of tools, implemented in Python, for the extraction of digital artifacts from volatile memory (RAM) samples.
Read more
rdd is a forensic copy program developed at and used by the Netherlands Forensic Institute (NFI). rdd is a file and device copying utility.
Read more
The forensic imager contained in this package, guymager, was designed to support different image file formats, to be most user-friendly and to run fast.
Read more
Radare2 is a portable reversing framework. It’s both a forensics tool and a debugger.
Read more
dcfldd is an enhanced version of dd with features useful for forensics and security. dcfldd is free and open source software.
Read more