A curated list of awesome forensic analysis tools and resources
-
Updated
May 26, 2023
A curated list of awesome forensic analysis tools and resources
UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.
The best tools and resources for forensic analysis.
A Volatility plugin for finding sqlite database rows
This will compile a list of Android, iOS, Linux malware techniques for attacking and detection purposes.
A live forensic collection script for UNIX-like systems.
An updated C# port of X-Ways X-Tensions API.
Extract valid or partially valid domain names and IPs from malicious or invalid URLs.
Docker images of open source forensic tools
LiveDiff is a portable system-level differencing tool for Microsoft Windows-based operating systems
Access Expert Witness Format (ewf/E01/L01) files using Golang
CTF Suite is a collection of tools you can use during Capture The Flag competitions. These tools are aimed at specific categories of problems and are specific to Jeopardy-style CTFs.
A python-based tool to extract forensic info from ActivitiesCache.db (Windows Activity Timeline)
Dockerized Kali Linux + Ubuntu 20.04 for Bug Bounty, Penetration Testing, Security Research, Computer Forensics and Reverse Engineering
This repository contains the forensic tools we made.
CellXML-Registry.exe is a portable Windows tool that parses an offline Windows Registry hive file and converts it to the RegXML format. CellXML-Registry leverages the Registry parser project by Eric Zimmerman to aid in parsing the Registry structure.
Crypto implementations analysis toolkit
Guymager is a free forensic imager for media acquisition. It is based on libewf and libguytools.
Add a description, image, and links to the computer-forensics topic page so that developers can more easily learn about it.
To associate your repository with the computer-forensics topic, visit your repo's landing page and select "manage topics."