DFIR Tool Catalog

42 tools across 11 forensic categories. Open-source (28), free (6), commercial (8).

Acquisition

8

AVML

Microsoft

Open Source

Microsoft-maintained Linux memory acquisition tool producing LiME-format output. Static binary; no kernel modules required.

Linux
Official site

dc3dd

Open Source

Patched version of GNU dd with forensic features: on-the-fly hashing, progress display, error handling, multi-hash output. Standard Linux-based physical imaging tool.

LinuxmacOS
Official site

FTK Imager

Exterro

Free

Free forensic imaging tool for creating bit-for-bit disk images, memory captures, and logical evidence extraction. Widely used Windows-based imaging workflow.

Windows
Official site

GRR Rapid Response

Google

Open Source

Google Rapid Response framework for remote live forensics at scale. Client-server architecture with flow-based collection and analysis.

WindowsLinuxmacOS
Official site

KAPE

Kroll

Free

Kroll Artifact Parser and Extractor. Triage-focused collection framework for high-value Windows forensic artifacts. Free for non-commercial use.

Windows
Official site

LiME

Open Source

Linux Memory Extractor kernel module. Captures raw RAM with minimal disturbance; output format compatible with Volatility.

Linux
Official site

Velociraptor

Open Source

Open-source endpoint forensics and hunting platform with VQL query language. Remote triage, continuous monitoring, and artifact-based hunts across Windows/Linux/macOS fleets.

WindowsLinuxmacOS
Official site

WinPMem

Open Source

Open-source Windows memory acquisition tool. Part of the Volatility Foundation; produces raw and ELF-format RAM captures.

Windows
Official site

Triage

2

CrowdResponse

CrowdStrike

Free

CrowdStrike's free Windows IR triage tool. Modular collection of system state, artifacts, and running-process data for rapid analysis.

Windows
Official site

Cyber Triage

Sleuth Kit Labs

Commercial

Commercial triage tool for rapid Windows endpoint analysis. Focus on analyst efficiency for rapid scope determination.

Windows
Official site

Memory Forensics

3

MemProcFS

Open Source

Exposes memory dumps as a filesystem. Combine with forensic tools that work on regular files to analyze RAM contents without bespoke Volatility plugins.

WindowsLinux
Official site

Rekall

Google

Open Source

Open-source memory-analysis framework (Google). Alternative to Volatility with strong Windows 10 support. No longer actively maintained but still useful.

WindowsLinuxmacOS
Official site

Volatility 3

Open Source

Python-based memory forensics framework. Parses raw RAM dumps for processes, network connections, loaded modules, injected code, rootkits, and encryption keys.

WindowsLinuxmacOS
Official site

Disk Forensics

6

Autopsy

Basis Technology

Open Source

Open-source digital forensics platform with GUI. Built on The Sleuth Kit; provides timeline analysis, keyword search, registry parsing, and artifact-extraction modules.

WindowsLinuxmacOS
Official site

EnCase Forensic

OpenText

Commercial

Established commercial forensic analysis suite. E01 evidence file format is an industry de facto standard; strong court-admissibility track record.

Windows
Official site

Eric Zimmerman's Tools

Free

Collection of free Windows forensic tools: EvtxECmd, RECmd, MFTECmd, AppCompatCacheParser, AmcacheParser, PECmd, SBECmd, and many more. Standard toolkit for Windows forensics.

Windows
Official site

Magnet AXIOM

Magnet Forensics

Commercial

Commercial forensic analysis platform unifying computer, mobile, and cloud evidence. Strong artifact-extraction for modern apps and cloud services.

Windows
Official site

The Sleuth Kit

Open Source

Command-line filesystem forensics toolkit. Parses NTFS, FAT, ExFAT, ext, HFS+, APFS, ISO 9660, and more. Foundation for Autopsy and many custom workflows.

LinuxmacOSWindows
Official site

X-Ways Forensics

X-Ways Software Technology

Commercial

Commercial Windows-based forensic analysis platform known for speed and efficiency. Strong file-carving, hash-database, and keyword-search capabilities.

Windows
Official site

Timeline

1

Timesketch

Google

Open Source

Collaborative forensic timeline analysis platform (Google). Web UI for multi-analyst timeline review with tagging, star, story, and Sigma-rule support.

Linux
Official site

Log Analysis

3

Chainsaw

WithSecure

Open Source

Fast Rust-based EVTX hunter with Sigma support. Ideal for rapid event log triage across large EVTX collections.

WindowsLinuxmacOS
Official site

Hayabusa

Open Source

Windows event log fast forensics timeline generator with Sigma support. Produces security event timelines from EVTX at scale.

WindowsLinuxmacOS
Official site

Plaso / log2timeline

Open Source

Python-based super-timeline generator. Parses hundreds of artifact types from filesystem, registry, logs, browsers, and more into a unified timeline.

LinuxmacOSWindows
Official site

Network Forensics

4

Arkime

Open Source

Open-source large-scale PCAP capture, indexing, and search (formerly Moloch). Enables query-driven access to long-retention packet data.

Linux
Official site

Suricata

Open Source

High-performance IDS/IPS and network-security monitoring engine. Rule-based detection with signature compatibility with Snort; also produces rich protocol logs.

LinuxWindowsmacOS
Official site

Wireshark

Open Source

Graphical packet analyzer. Standard tool for PCAP inspection with hundreds of protocol dissectors.

WindowsLinuxmacOS
Official site

Zeek

Open Source

Network analysis framework (formerly Bro). Generates structured, protocol-aware logs (conn, http, ssl, dns, files) from PCAP or live traffic. Foundation for network-layer forensics.

Linux
Official site

Malware Analysis

4

Cuckoo Sandbox

Open Source

Open-source automated malware analysis system. Detonates suspicious files in isolated VMs and captures behavior.

Linux
Official site

Ghidra

NSA

Open Source

NSA-developed open-source software reverse engineering framework. Disassembler, decompiler, and analysis platform; primary alternative to IDA Pro.

WindowsLinuxmacOS
Official site

IDA Pro

Hex-Rays

Commercial

Industry-standard commercial disassembler and decompiler. Strong plugin ecosystem; premium tool for malware reverse engineering.

WindowsLinuxmacOS
Official site

YARA

Open Source

Pattern-matching engine for malware researchers. De facto standard for expressing and sharing malware-identification rules.

WindowsLinuxmacOS
Official site

Cloud Forensics

3

AWS CloudTrail

AWS

Free

AWS management-plane audit log. Primary evidence source for AWS forensic investigations; best analyzed via Athena with partitioned queries.

Cloud & SaaS
Official site

Cado Security Platform

Cado Security

Commercial

Commercial cloud-native digital forensics platform. Automated cloud evidence collection and analysis for AWS, Azure, GCP, and container workloads.

Cloud & SaaS
Official site

Google Cloud Forensics Utils

Google

Open Source

Open-source Python library for AWS, Azure, GCP forensic collection. Snapshots, disk copies, log exports, and triage workflows across providers.

Linux
Official site

Mobile Forensics

4

Cellebrite UFED

Cellebrite

Commercial

Industry-standard commercial mobile forensics platform. Physical, logical, and file-system extraction for iOS and Android; supports checkm8 and other acquisition exploits.

iOSAndroid
Official site

iLEAPP / ALEAPP

Open Source

Open-source iOS (iLEAPP) and Android (ALEAPP) logs, events, and properties parsers. Community-maintained mobile-artifact parser with HTML reporting.

iOSAndroid
Official site

Magnet AXIOM Mobile

Magnet Forensics

Commercial

Commercial mobile forensics product integrated with AXIOM. Supports iOS and Android acquisition and analysis with unified reporting.

iOSAndroid
Official site

MVT (Mobile Verification Toolkit)

Amnesty International

Open Source

Amnesty International's open-source tool for detecting spyware indicators on iOS and Android devices. Built around known-IoC and behavioral detection.

iOSAndroid
Official site

Detection

4

Falco

Open Source

Open-source cloud-native runtime security. eBPF-based kernel instrumentation for anomalous container and Linux host behavior detection.

Linux
Official site

osquery

Open Source

Open-source endpoint instrumentation framework exposing OS state as SQL-queryable tables. Linux, macOS, Windows. Widely used for fleet-wide triage.

WindowsLinuxmacOS
Official site

Sigma

Open Source

Vendor-neutral YAML-based detection rule format. Converts to SIEM-specific query languages (KQL, SPL, EQL); community-maintained rule repository.

WindowsLinuxmacOS
Official site

Sysmon

Microsoft

Free

Microsoft Sysinternals driver providing detailed Windows system activity logging. Critical pre-deployment forensic instrumentation when EDR is absent.

Windows
Official site