Tools: forensic (94)
Pentesting tools tagged forensic. See all tools or the category key.
aimage
A tool to create aff-images.
air
A GUI front-end to dd/dc3dd designed for easily creating forensic images.
analyzemft
Parse the MFT file from an NTFS filesystem.
bmap-tools
Tool for copying largely sparse files using information from a block map file.
bmc-tools
RDP Bitmap Cache parser.
canari
Maltego rapid transform development and execution framework.
captipper
Malicious HTTP traffic explorer tool.
casefile
The little brother to Maltego without transforms, but combines graph and link analysis to examine links between manually
chaosmap
An information gathering tool and dns / whois / web server scanner
chromefreak
A Cross-Platform Forensic Framework for Google Chrome
dfir-ntfs
An NTFS parser for digital forensics & incident response.
dftimewolf
Framework for orchestrating forensic collection, processing and data export.
disitool
Tool to work with Windows executables digital signatures.
dmde
Disk Editor and Data Recovery Software.
dmg2img
A CLI tool to uncompress Apple's compressed DMG files to the HFS+ IMG format.
dshell
A network forensic analysis framework.
eindeutig
Examine the contents of Outlook Express DBX email repository files.
emldump
Analyze MIME files.
evtkit
Fix acquired .evt - Windows Event Log files (Forensics).
extractusnjrnl
Tool to extract the $UsnJrnl from an NTFS volume.
firefox-decrypt
Extract passwords from Mozilla Firefox, Waterfox, Thunderbird, SeaMonkey profiles.
fridump
A universal memory dumper using Frida.
gspy
Forensic goroutine-to-syscall inspector for live Go processes.
imagemounter
Command line utility and Python package to ease the (un)mounting of forensic disk images.
indx2csv
An advanced parser for INDX records.
indxcarver
Carve INDX records from a chunk of data.
indxparse
A Tool suite for inspecting NTFS artifacts.
interrogate
A proof-of-concept tool for identification of cryptographic keys in binary material (regardless of target operating syst
iosforensic
iOS forensic tool.
ipba2
IOS Backup Analyzer.
iphoneanalyzer
Allows you to forensically examine or recover date from in iOS device.
jefferson
JFFS2 filesystem extraction tool.
lazagne
An open source application used to retrieve lots of passwords stored on a local computer.
ldsview
Offline search tool for LDAP directory dumps in LDIF format.
lfle
Recover event log entries from an image by heurisitically looking for record structures.
libfvde
Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes.
limeaide
Remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.
log-file-parser
Parser for $LogFile on NTFS.
loki-scanner
Simple IOC and Incident Response Scanner.
make-pdf
This tool will embed javascript inside a PDF document.
malheur
A tool for the automatic analyze of malware behavior.
malwaredetect
Submits a file's SHA1 sum to VirusTotal to determine whether it is a known piece of malware
mboxgrep
A small, non-interactive utility that scans mail folders for messages matching regular expressions. It does matching aga
memfetch
Dumps any userspace process memory without affecting its execution.
mft2csv
Extract $MFT record info and log it to a csv file.
mftcarver
Carve $MFT records from a chunk of data (for instance a memory dump).
mftrcrd
Command line $MFT record decoder.
mftref2name
Resolve file index number to name or vice versa on NTFS.
mimipenguin
A tool to dump the login password from the current linux user.
mobiusft
An open-source forensic framework written in Python/GTK that manages cases and case items, providing an abstract interfa
mp3nema
A tool aimed at analyzing and capturing data that is hidden between frames in an MP3 file or stream, otherwise noted as
mxtract
Memory Extractor & Analyzer.
naft
Network Appliance Forensic Toolkit.
netspionage
Network Forensics CLI utility that performs Network Scanning, OSINT, and Attack Detection.
networkminer
A Network Forensic Analysis Tool for advanced Network Traffic Analysis, sniffer and packet analyzer.
nfex
A tool for extracting files from the network in real-time or post-capture from an offline tcpdump pcap savefile.
ntdsxtract
Active Directory forensic framework.
ntfs-file-extractor
Extract files off NTFS.
ntfs-log-tracker
This tool can parse $LogFile, $UsnJrnl of NTFS.
parse-evtx
A tool to parse the Windows XML Event Log (EVTX) format.
pcapxray
A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, h
pdblaster
Extract PDB file paths from large sample sets of executable files.
pdfbook-analyzer
Utility for facebook memory forensics.
pdfresurrect
A tool aimed at analyzing PDF documents.
peepdf
A Python tool to explore PDF files in order to find out if the file can be harmful or not.
pev
Command line based tool for PE32/PE32+ file analysis.
powermft
Powerful commandline $MFT record editor.
python-flow.record
Recordization library.
python2-peepdf
A Python tool to explore PDF files in order to find out if the file can be harmful or not.
rcrdcarver
Carve RCRD records ($LogFile) from a chunk of data..
recentfilecache-parser
Python parser for the RecentFileCache.bcf on Windows.
recuperabit
A tool for forensic file system reconstruction.
regipy
Library for parsing offline registry hives.
regrippy
Framework for reading and extracting useful forensics data from Windows registry hives.
rekall
Memory Forensic Framework.
replayproxy
Forensic tool to replay web-based attacks (and also general HTTP traffic) that were captured in a pcap file.
secure2csv
Decode security descriptors in $Secure on NTFS.
shadowexplorer
Browse the Shadow Copies created by the Windows Vista / 7 / 8 / 10 Volume Shadow Copy Service.
skypefreak
A Cross Platform Forensic Framework for Skype.
swap-digger
A tool used to automate Linux swap analysis during post-exploitation or forensics.
tchunt-ng
Reveal encrypted files stored on a filesystem.
tekdefense-automater
IP URL and MD5 OSINT Analysis
thumbcacheviewer
Extract Windows thumbcache database files.
trid
An utility designed to identify file types from their binary signatures.
truehunter
Detect TrueCrypt containers using a fast and memory efficient approach.
usbrip
USB device artifacts tracker.
usnjrnl2csv
Parser for $UsnJrnl on NTFS.
usnparser
A Python script to parse the NTFS USN journal.
vipermonkey
A VBA parser and emulation engine to analyze malicious macros.
volafox
Mac OS X Memory Analysis Toolkit.
volatility-extra
Volatility plugins developed and maintained by the community.
windows-prefetch-parser
Parse Windows Prefetch files.
wmi-forensics
Scripts used to find evidence in WMI repositories.
zipdump
ZIP dump utility.