Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

SIFT

SANS forensic workstation for digital forensics and incident response

forensicsbased on UbuntuBlue Team

SIFT has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗

Last verified September 5, 2026

SIFT is a forensic workstation maintained by SANS, distributed as a ready-to-use environment for digital forensics and incident response work rather than a full standalone desktop distribution.

Use it only against systems/media you own or are explicitly authorized to examine — see the disclaimer.

Notable bundled toolsmanually maintained

bulk-extractor

Extracts information without parsing filesystem

plaso

Super timeline all the things – metapackage

sleuthkit

Tools for forensics analysis on volume and filesystem data

Volatility Framework

Memory forensics tool and framework.

Getting started

SIFT (SANS Investigative Forensic Toolkit) ships as a VM appliance (OVA), a native Ubuntu 22.04 installer package, or via WSL on Windows. SANS' own site lists roughly 30 bundled tools by name, but without per-tool links or descriptions, so there's no structured catalog to point to beyond that list. It's commonly paired with REMnux for combined forensics and malware-analysis workflows.