Forensic Software & Applications
Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.
CyLR
Alan Orlikoski (Open Source) • Windows
A lightweight live-response tool for quickly collecting key forensic artifacts from Windows systems.
GRR Rapid Response
Google (Open Source) • Server + Agent (Windows/Linux/macOS)
Google's remote live forensics and incident response framework based on a client-server architecture.
KAPE
Eric Zimmerman / Kroll • Windows
Kroll Artifact Parser and Extractor — a fast triage tool for collecting and immediately processing Windows forensic artifacts.
UAC
Thiago Lahr / tclahr (Open Source) • Linux / macOS / AIX / Solaris (shell script)
Unix-like Artifacts Collector — a pure shell-script live response tool for Unix-like systems.
Velociraptor
Rapid7 (Open Source) • Server + Agent (Windows/Linux/macOS)
Open-source endpoint monitoring and DFIR platform featuring the highly flexible VQL query language.