Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: forensic (94)

Pentesting tools tagged forensic. See all tools or the category key.

Team (best effort)

aimage

A tool to create aff-images.

forensic Blue Team

air

A GUI front-end to dd/dc3dd designed for easily creating forensic images.

forensic Blue Team

analyzemft

Parse the MFT file from an NTFS filesystem.

forensic Blue Team

bmap-tools

Tool for copying largely sparse files using information from a block map file.

forensic Blue Team

bmc-tools

RDP Bitmap Cache parser.

forensic Blue Team

canari

Maltego rapid transform development and execution framework.

forensic Blue Team

captipper

Malicious HTTP traffic explorer tool.

forensic Blue Team

casefile

The little brother to Maltego without transforms, but combines graph and link analysis to examine links between manually

forensic Blue Team

chaosmap

An information gathering tool and dns / whois / web server scanner

forensic Blue Team

chromefreak

A Cross-Platform Forensic Framework for Google Chrome

forensic Blue Team

dfir-ntfs

An NTFS parser for digital forensics & incident response.

forensic Blue Team

dftimewolf

Framework for orchestrating forensic collection, processing and data export.

forensic Blue Team

disitool

Tool to work with Windows executables digital signatures.

forensic Blue Team

dmde

Disk Editor and Data Recovery Software.

forensic Blue Team

dmg2img

A CLI tool to uncompress Apple's compressed DMG files to the HFS+ IMG format.

forensic Blue Team

dshell

A network forensic analysis framework.

forensic Blue Team

eindeutig

Examine the contents of Outlook Express DBX email repository files.

forensic Blue Team

emldump

Analyze MIME files.

forensic Blue Team

evtkit

Fix acquired .evt - Windows Event Log files (Forensics).

forensic Blue Team

extractusnjrnl

Tool to extract the $UsnJrnl from an NTFS volume.

forensic Blue Team

firefox-decrypt

Extract passwords from Mozilla Firefox, Waterfox, Thunderbird, SeaMonkey profiles.

forensic Blue Team

fridump

A universal memory dumper using Frida.

forensic Blue Team

gspy

Forensic goroutine-to-syscall inspector for live Go processes.

forensic Blue Team

imagemounter

Command line utility and Python package to ease the (un)mounting of forensic disk images.

forensic Blue Team

indx2csv

An advanced parser for INDX records.

forensic Blue Team

indxcarver

Carve INDX records from a chunk of data.

forensic Blue Team

indxparse

A Tool suite for inspecting NTFS artifacts.

forensic Blue Team

interrogate

A proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating syst

forensic Blue Team

iosforensic

iOS forensic tool.

forensic Blue Team

ipba2

IOS Backup Analyzer.

forensic Blue Team

iphoneanalyzer

Allows you to forensically examine or recover date from in iOS device.

forensic Blue Team

jefferson

JFFS2 filesystem extraction tool.

forensic Blue Team

lazagne

An open source application used to retrieve lots of passwords stored on a local computer.

forensic Blue Team

ldsview

Offline search tool for LDAP directory dumps in LDIF format.

forensic Blue Team

lfle

Recover event log entries from an image by heurisitically looking for record structures.

forensic Blue Team

libfvde

Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes.

forensic Blue Team

limeaide

Remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.

forensic Blue Team

log-file-parser

Parser for $LogFile on NTFS.

forensic Blue Team

loki-scanner

Simple IOC and Incident Response Scanner.

forensic Blue Team

make-pdf

This tool will embed javascript inside a PDF document.

forensic Blue Team

malheur

A tool for the automatic analyze of malware behavior.

forensic Blue Team

malwaredetect

Submits a file's SHA1 sum to VirusTotal to determine whether it is a known piece of malware

forensic Blue Team

mboxgrep

A small, non-interactive utility that scans mail folders for messages matching regular expressions. It does matching aga

forensic Blue Team

memfetch

Dumps any userspace process memory without affecting its execution.

forensic Blue Team

mft2csv

Extract $MFT record info and log it to a csv file.

forensic Blue Team

mftcarver

Carve $MFT records from a chunk of data (for instance a memory dump).

forensic Blue Team

mftrcrd

Command line $MFT record decoder.

forensic Blue Team

mftref2name

Resolve file index number to name or vice versa on NTFS.

forensic Blue Team

mimipenguin

A tool to dump the login password from the current linux user.

forensic Blue Team

mobiusft

An open-source forensic framework written in Python/GTK that manages cases and case items, providing an abstract interfa

forensic Blue Team

mp3nema

A tool aimed at analyzing and capturing data that is hidden between frames in an MP3 file or stream, otherwise noted as

forensic Blue Team

mxtract

Memory Extractor & Analyzer.

forensic Blue Team

naft

Network Appliance Forensic Toolkit.

forensic Blue Team

netspionage

Network Forensics CLI utility that performs Network Scanning, OSINT, and Attack Detection.

forensic Blue Team

networkminer

A Network Forensic Analysis Tool for advanced Network Traffic Analysis, sniffer and packet analyzer.

forensic Blue Team

nfex

A tool for extracting files from the network in real-time or post-capture from an offline tcpdump pcap savefile.

forensic Blue Team

ntdsxtract

Active Directory forensic framework.

forensic Blue Team

ntfs-file-extractor

Extract files off NTFS.

forensic Blue Team

ntfs-log-tracker

This tool can parse $LogFile, $UsnJrnl of NTFS.

forensic Blue Team

parse-evtx

A tool to parse the Windows XML Event Log (EVTX) format.

forensic Blue Team

pcapxray

A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, h

forensic Blue Team

pdblaster

Extract PDB file paths from large sample sets of executable files.

forensic Blue Team

pdfbook-analyzer

Utility for facebook memory forensics.

forensic Blue Team

pdfresurrect

A tool aimed at analyzing PDF documents.

forensic Blue Team

peepdf

A Python tool to explore PDF files in order to find out if the file can be harmful or not.

forensic Blue Team

pev

Command line based tool for PE32/PE32+ file analysis.

forensic Blue Team

powermft

Powerful commandline $MFT record editor.

forensic Blue Team

python-flow.record

Recordization library.

forensic Blue Team

python2-peepdf

A Python tool to explore PDF files in order to find out if the file can be harmful or not.

forensic Blue Team

rcrdcarver

Carve RCRD records ($LogFile) from a chunk of data..

forensic Blue Team

recentfilecache-parser

Python parser for the RecentFileCache.bcf on Windows.

forensic Blue Team

recuperabit

A tool for forensic file system reconstruction.

forensic Blue Team

regipy

Library for parsing offline registry hives.

forensic Blue Team

regrippy

Framework for reading and extracting useful forensics data from Windows registry hives.

forensic Blue Team

rekall

Memory Forensic Framework.

forensic Blue Team

replayproxy

Forensic tool to replay web-based attacks (and also general HTTP traffic) that were captured in a pcap file.

forensic Blue Team

secure2csv

Decode security descriptors in $Secure on NTFS.

forensic Blue Team

shadowexplorer

Browse the Shadow Copies created by the Windows Vista / 7 / 8 / 10 Volume Shadow Copy Service.

forensic Blue Team

skypefreak

A Cross Platform Forensic Framework for Skype.

forensic Blue Team

swap-digger

A tool used to automate Linux swap analysis during post-exploitation or forensics.

forensic Blue Team

tchunt-ng

Reveal encrypted files stored on a filesystem.

forensic Blue Team

tekdefense-automater

IP URL and MD5 OSINT Analysis

forensic Blue Team

thumbcacheviewer

Extract Windows thumbcache database files.

forensic Blue Team

trid

An utility designed to identify file types from their binary signatures.

forensic Blue Team

truehunter

Detect TrueCrypt containers using a fast and memory efficient approach.

forensic Blue Team

usbrip

USB device artifacts tracker.

forensic Blue Team

usnjrnl2csv

Parser for $UsnJrnl on NTFS.

forensic Blue Team

usnparser

A Python script to parse the NTFS USN journal.

forensic Blue Team

vipermonkey

A VBA parser and emulation engine to analyze malicious macros.

forensic Blue Team

volafox

Mac OS X Memory Analysis Toolkit.

forensic Blue Team

volatility-extra

Volatility plugins developed and maintained by the community.

forensic Blue Team

windows-prefetch-parser

Parse Windows Prefetch files.

forensic Blue Team

wmi-forensics

Scripts used to find evidence in WMI repositories.

forensic Blue Team

zipdump

ZIP dump utility.

forensic Blue Team