Skip to content

DFIR ORC

Forensics & Incident Response

DFIR ORC is a collection of specialized tools dedicated to reliably parse and collect critical artifacts such as the MFT, registry hives or event logs. DFIR ORC collects data, but does not analyze it: it is not meant to triage machines. It provides a forensically relevant snapshot of machines running Microsoft Windows. The code can be found on GitHub.

C++ Latest v10.3.1 · 2d ago Security brief →

Recent releases

View all 2 releases →
No immediate action
v10.3.1 Bugfix

Memory usage fix

Review required
v10.3.0 Breaking risk
Auth Dependencies

OrcCapsule, WolfLauncher multi-instance, ToolEmbed /embed

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
439
Forks
49
Languages
C++ CMake PowerShell

Install & Platforms

Install via
winget
Platforms
windows

Beta — feedback welcome: [email protected]