SIFT
SANS forensic workstation for digital forensics and incident response
SIFT has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
Last verified September 5, 2026
SIFT is a forensic workstation maintained by SANS, distributed as a ready-to-use environment for digital forensics and incident response work rather than a full standalone desktop distribution.
Use it only against systems/media you own or are explicitly authorized to examine — see the disclaimer.
Notable bundled toolsmanually maintained
bulk-extractor
Extracts information without parsing filesystem
plaso
Super timeline all the things – metapackage
sleuthkit
Tools for forensics analysis on volume and filesystem data
Volatility Framework
Memory forensics tool and framework.
Getting started
SIFT (SANS Investigative Forensic Toolkit) ships as a VM appliance (OVA), a native Ubuntu 22.04 installer package, or via WSL on Windows. SANS' own site lists roughly 30 bundled tools by name, but without per-tool links or descriptions, so there's no structured catalog to point to beyond that list. It's commonly paired with REMnux for combined forensics and malware-analysis workflows.