Skip to content

Forensic Software & Applications

Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.

Scalpel

Golden G. Richard III (Open Source) • Windows / Linux / macOS

41 20

High-performance open-source file carving tool, rewritten from Foremost.

View Details Download

Sleuth Kit

Brian Carrier (Open Source) • Windows / Linux / macOS (CLI + library)

64 37

A collection of command-line tools and a C library for analyzing volume and file system structures on forensic disk images.

View Details Download

Snort

Cisco (Open Source) • Linux / Windows

38 31

Open-source, signature-based network intrusion detection and prevention system (IDS/IPS).

View Details Download

Suricata

Open Information Security Foundation (Open Source) • Linux / Windows / macOS

40 22

A next-generation IDS/IPS and network security monitoring engine with full multi-threading support.

View Details Download

TestDisk

Christophe Grenier / CGSecurity (Open Source) • Windows / Linux / macOS

39 28

Open-source tool for repairing damaged partition tables and recovering deleted partitions.

View Details Download

Timesketch

Google (Open Source) • Web-based (Linux server)

41 30

Google's collaborative web-based platform for analyzing and managing forensic timelines as a team.

View Details Download

UAC

Thiago Lahr / tclahr (Open Source) • Linux / macOS / AIX / Solaris (shell script)

43 16

Unix-like Artifacts Collector — a pure shell-script live response tool for Unix-like systems.

View Details Download

USB Write Blocker

Open Source • Windows

41 23

A registry-based utility for enabling software-based write protection on USB devices.

View Details Download

Velociraptor

Rapid7 (Open Source) • Server + Agent (Windows/Linux/macOS)

41 17

Open-source endpoint monitoring and DFIR platform featuring the highly flexible VQL query language.

View Details Download
v3.2.0

Volatility

Volatility Foundation (Open Source) • Windows / Linux / macOS (Python)

70 68

The most widely used open-source memory analysis framework for extracting processes, network connections, and malware artifacts from RAM dumps.

View Details Download

WinFE

WinFE Community (Open Source) • Bootable Windows PE

45 23

A Windows PE-based bootable forensic environment configured read-only for safe evidence acquisition.

View Details Download

WinPmem

Velocidex / Rekall (Open Source) • Windows

41 17

Open-source driver and utility for forensically acquiring Windows physical memory.

View Details Download