Forensic Software & Applications
Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.
Log2Timeline
Plaso Project (Open Source) • Windows / Linux / macOS (Python)
The super-timeline generation engine at the core of the Plaso framework, merging thousands of artifact sources into a single timeline.
LoginTracer
JPCERT/CC (Open Source) • Web-based (Linux server)
A visualization tool (also known as LogonTracer) for analyzing Active Directory logon events and detecting lateral movement.
Magnet RAM Capture
Magnet Forensics • Windows 11 / 10 x64
A free, lightweight, and portable forensic tool designed to capture the physical memory (RAM) of a suspect's Windows computer.
Metadata++
Open Source • Windows
A companion utility for reviewing and managing file metadata in bulk.
NetworkMiner
Netresec (Open Source Edition) • Windows / Linux
A passive Network Forensic Analysis Tool (NFAT) for extracting files, credentials, and sessions from network traffic captures.
NTFS Tool
Open Source • Windows
A supporting utility for examining the internal structure of the NTFS file system on forensic images.
PcapXray
Srinivas (Open Source) • Windows / Linux / macOS (Python)
A PCAP analysis tool that visualizes network traffic as an interactive graph/map.
PhotoRec
Christophe Grenier / CGSecurity (Open Source) • Windows / Linux / macOS
Open-source file carving companion to TestDisk for recovering lost files from various media.
Ram Capture
Belkasoft • Windows
A lightweight, free utility to acquire (dump) the full contents of RAM on a running Windows system.
Ratool
Open Source • Windows
A utility to help analyze and control read/write access on removable storage media.
RecuperaBit
Andrea Lazzarotto (Open Source) • Windows / Linux / macOS (Python)
Open-source tool for reconstructing damaged NTFS partition structures and recovering data.
RegRipper
Harlan Carvey (Open Source) • Windows / Linux / macOS (Perl)
Industry-standard open-source tool for extracting and parsing data from Windows Registry hives.