Forensic Software & Applications
Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.
Chainsaw
WithSecure Labs (Open Source) • Windows / Linux / macOS
Fast Rust-based hunting tool for searching threat indicators in Windows Event Logs using Sigma rules.
Hayabusa
Yamato Security (Open Source) • Windows / Linux / macOS
Rust-based Windows event log threat hunting and forensics tool with built-in Sigma rule support.
LoginTracer
JPCERT/CC (Open Source) • Web-based (Linux server)
A visualization tool (also known as LogonTracer) for analyzing Active Directory logon events and detecting lateral movement.
NTFS Tool
Open Source • Windows
A supporting utility for examining the internal structure of the NTFS file system on forensic images.
RecuperaBit
Andrea Lazzarotto (Open Source) • Windows / Linux / macOS (Python)
Open-source tool for reconstructing damaged NTFS partition structures and recovering data.
RegRipper
Harlan Carvey (Open Source) • Windows / Linux / macOS (Perl)
Industry-standard open-source tool for extracting and parsing data from Windows Registry hives.