Skip to content

Forensic Software & Applications

Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.

ALEAPP

Alexis Brignoni (Open Source) • Windows / Linux / macOS (Python)

48 36

Open-source parser for extracting and analyzing logs, events, and protobufs from Android forensic extractions.

View Details Download

Arkime

Arkime Project / AOL (Open Source) • Linux (server)

41 26

Large-scale full packet capture and search system for recording and indexing all network traffic.

View Details Download

ArtEx

Open Source • Windows / Linux

40 19

An artifact extraction utility supporting the initial analysis stage of mobile device data.

View Details Download
v4.21.0

Autopsy

Basis Technology (Open Source) • Windows / Linux / macOS

70 72

Open-source digital forensics platform with a graphical interface for analyzing disk images, artifacts, and timelines in one place.

View Details Download

Binwalk

ReFirm Labs (Open Source) • Linux / macOS (Python)

43 36

Firmware analysis tool for identifying and extracting embedded file systems and content.

View Details Download

Chainsaw

WithSecure Labs (Open Source) • Windows / Linux / macOS

38 31

Fast Rust-based hunting tool for searching threat indicators in Windows Event Logs using Sigma rules.

View Details Download

CyLR

Alan Orlikoski (Open Source) • Windows

46 34

A lightweight live-response tool for quickly collecting key forensic artifacts from Windows systems.

View Details Download

Dc3dd

DC3 — DoD Cyber Crime Center (Open Source) • Linux

48 35

A patched version of GNU dd with added hashing and logging features for forensic imaging needs.

View Details Download

DFIRTimewolf

Google (Open Source) • Linux / Python (CLI)

42 31

Google's open-source orchestration framework for chaining automated forensic collection and processing workflows.

View Details Download

Disk-Arbitrator

Aaron Burghardt (Open Source) • macOS

42 33

macOS utility to prevent auto-mounting and enforce read-only mode on external media during forensic work.

View Details Download

Ewfacquire

libewf Project (Open Source) • Linux / Windows (CLI)

41 34

Command-line tool from libewf for acquiring storage media into the Expert Witness Format (E01).

View Details Download

ExifTool

Phil Harvey (Open Source) • Windows / Linux / macOS

42 33

Industry-standard utility for reading, writing, and editing metadata across hundreds of file types.

View Details Download