Forensic Software & Applications
Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.
Scalpel
Golden G. Richard III (Open Source) • Windows / Linux / macOS
High-performance open-source file carving tool, rewritten from Foremost.
Sleuth Kit
Brian Carrier (Open Source) • Windows / Linux / macOS (CLI + library)
A collection of command-line tools and a C library for analyzing volume and file system structures on forensic disk images.
Snort
Cisco (Open Source) • Linux / Windows
Open-source, signature-based network intrusion detection and prevention system (IDS/IPS).
Suricata
Open Information Security Foundation (Open Source) • Linux / Windows / macOS
A next-generation IDS/IPS and network security monitoring engine with full multi-threading support.
TestDisk
Christophe Grenier / CGSecurity (Open Source) • Windows / Linux / macOS
Open-source tool for repairing damaged partition tables and recovering deleted partitions.
Timesketch
Google (Open Source) • Web-based (Linux server)
Google's collaborative web-based platform for analyzing and managing forensic timelines as a team.
UAC
Thiago Lahr / tclahr (Open Source) • Linux / macOS / AIX / Solaris (shell script)
Unix-like Artifacts Collector — a pure shell-script live response tool for Unix-like systems.
USB Write Blocker
Open Source • Windows
A registry-based utility for enabling software-based write protection on USB devices.
Velociraptor
Rapid7 (Open Source) • Server + Agent (Windows/Linux/macOS)
Open-source endpoint monitoring and DFIR platform featuring the highly flexible VQL query language.
Volatility
Volatility Foundation (Open Source) • Windows / Linux / macOS (Python)
The most widely used open-source memory analysis framework for extracting processes, network connections, and malware artifacts from RAM dumps.
WinFE
WinFE Community (Open Source) • Bootable Windows PE
A Windows PE-based bootable forensic environment configured read-only for safe evidence acquisition.
WinPmem
Velocidex / Rekall (Open Source) • Windows
Open-source driver and utility for forensically acquiring Windows physical memory.