Forensic Software & Applications
Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.
Dc3dd
DC3 — DoD Cyber Crime Center (Open Source) • Linux
A patched version of GNU dd with added hashing and logging features for forensic imaging needs.
Disk-Arbitrator
Aaron Burghardt (Open Source) • macOS
macOS utility to prevent auto-mounting and enforce read-only mode on external media during forensic work.
Ewfacquire
libewf Project (Open Source) • Linux / Windows (CLI)
Command-line tool from libewf for acquiring storage media into the Expert Witness Format (E01).
FTK Imager
Exterro / AccessData • Windows
Industry-standard forensic imaging tool for bit-stream imaging (E01, RAW/DD) and evidence preview without altering the original data.
Guymager
Guy Voncken (Open Source) • Linux
Free forensic imaging application with a graphical interface for Linux, supporting E01, dd, and AFF formats.
TestDisk
Christophe Grenier / CGSecurity (Open Source) • Windows / Linux / macOS
Open-source tool for repairing damaged partition tables and recovering deleted partitions.
WinFE
WinFE Community (Open Source) • Bootable Windows PE
A Windows PE-based bootable forensic environment configured read-only for safe evidence acquisition.