Skip to content

Tools

Forensics & Incident Response tools 36 tools

Submit tool
Category
Health

36 tools

SIPCAPTURE Homer Healthy open source

Troubleshooting and monitoring VoIP calls.

beelzebub Healthy open source

Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.

VAST Healthy open source

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

Quark-Engine Mixed open source

An Obfuscation-Neglect Android Malware Scoring System.

Ghidra Healthy open source

Ghidra is a software reverse engineering (SRE) framework

Radare2 Healthy open source

UNIX-like reverse engineering framework and command-line toolset

OSSEC At Risk open source

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

memvid Mixed open source
Maigret Mixed open source

♂ Collect a dossier on a person by username from 3000+ sites

AVML Mixed open source

AVML - Acquire Volatile Memory for Linux

Chainsaw Mixed open source

Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.

Plaso At Risk open source

Super timeline all the things

Sysmon for Linux Mixed open source
ProcMon for Linux Mixed open source
FingerprintJS Mixed open source

The most advanced free and open-source browser fingerprinting library

Fastfinder At Risk open source

Fast customisable cross-platform suspicious file finder. Supports md5/sha1/sha256 hashs, litteral/wildcard strings, regular expressions and YARA rules. Can easily be packed to be deployed on any windows / linux host.

macOS Artifact Parsing Tool (mac_apt) At Risk open source

macOS (& ios) Artifact Parsing Tool

go-audit At Risk open source

go-audit is an alternative to the auditd daemon that ships with many distros

Forensic Artifacts At Risk open source

Digital Forensics Artifact Repository

Timesketch At Risk open source

Collaborative forensic timeline analysis

Dissect At Risk open source

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group).

Rizin Mixed open source

UNIX-like reverse engineering framework and command-line toolset.

Substation At Risk open source

A cloud native data pipeline and transformation toolkit for security teams.

Hindsight Mixed open source

Browser forensics tool for Google Chrome (and other Chromium-based browsers)

grr At Risk open source

GRR Rapid Response: remote live forensics for incident response

LiME At Risk open source

Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD.

CAPA At Risk open source

The FLARE team's open-source tool to identify capabilities in executable files.

Flare At Risk open source

A fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing.

NullSec LogReaper Mixed open source

High-speed log analysis and forensics tool with multi-format parsing, pattern matching, timeline reconstruction and anomaly detection for incident response.

Splunk Attack Range At Risk open source

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Acquire At Risk open source

Acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container. This makes Acquire an excellent tool to, among others, speedup the process of digital forensic triage. It uses Dissect to gather that information from the raw disk, if possible.

Velociraptor At Risk open source

Digging Deeper....

UAC At Risk open source

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

CyberChef Mixed open source

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

Zentral At Risk open source

Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.

Volatility 3 At Risk open source

Volatility 3.0 development

Beta — feedback welcome: [email protected]