EN
ENNA
๐Ÿ”ฌ

Digital Forensics

16 tools indexed

Digital forensics tools for disk imaging, memory analysis, file carving, log timeline reconstruction, and evidence preservation. Used by incident responders, law enforcement, and security analysts to investigate breaches and recover digital evidence.

Volatility 3

Python
Featured

Advanced memory forensics framework. Extracts artifacts from RAM dumps โ€” processes, network connections, registry.

memoryram-dumpartifact-extractionincident-response
4.0k6423d ago

Autopsy

Java

Digital forensics platform with GUI. Disk image analysis, timeline analysis, keyword search, hash filtering.

disk-forensicsguitimelinefile-carving
3.1k6561d ago

Ghidra

Java
Featured

NSA's reverse engineering framework. Disassembly, decompilation, graphing, and scripting for binary analysis.

reverse-engineeringdecompilerbinary-analysisnsa
66.6k7.3k3d ago

Binwalk

Python

Firmware analysis tool. Searches binary images for embedded files, executables, and file systems.

firmwarebinaryextractionembedded
13.8k1.8k1mo ago

YARA

C
Featured

Pattern matching swiss knife for malware researchers. Create rules to identify and classify malware samples.

malwarepattern-matchingrulesclassification
9.5k1.6k1mo ago

Velociraptor

Go
Featured

Endpoint visibility and collection tool. Hunt for artifacts across thousands of endpoints simultaneously.

endpointhuntingdfirartifact-collection
3.9k6023d ago

Plaso (log2timeline)

Python

Super timeline creation engine. Extracts timestamps from multiple forensic artifact sources into a single timeline.

timelinelog-analysisartifactsuper-timeline
2.0k4111mo ago

Radare2

C

Portable reversing framework. Disassembly, debugging, analysis, patching, and scripting in a single CLI.

reverse-engineeringdisassemblerdebuggerscripting
23.4k3.2k1d ago

Cutter

C++

GUI for Radare2. Makes reverse engineering accessible with graphs, decompiler, and hex editor built in.

reverse-engineeringguiradare2decompiler
18.6k1.3k5d ago

The Sleuth Kit

C

Collection of command-line tools for forensic analysis of disk images and file systems.

disk-forensicsfile-systemanalysisimaging
3.0k6792d ago

CyLR

C#

Live response collection tool for quickly gathering forensic artifacts from hosts during incident response.

incident-responseartifact-collectionlive-responsetriage
721953y ago

Chainsaw

Rust

Rapidly search and hunt through Windows forensic artifacts like event logs, MFT, and Shimcache using Sigma rules.

windows-forensicsevent-logssigma-rulesthreat-hunting
3.5k2964d ago

Hayabusa

Rust

Windows event log fast forensics timeline generator and threat hunting tool with built-in Sigma rule support.

windows-eventstimelinesigmadfir
3.1k26315d ago

oletools

Python

Python tools for analyzing OLE and MS Office files โ€” detect VBA macros, embedded objects, and malicious content.

office-analysisvba-macrosolemalware-analysis
3.3k5981mo ago

PE-sieve

C++

Scans running processes for suspicious in-memory modifications including hollowing, hooking, and code injection.

process-scanningmemory-forensicscode-injectionmalware-detection
3.6k4684d ago

capa

Python

Automatically identify capabilities in executable files โ€” detects techniques like persistence, C2, and anti-analysis.

malware-analysiscapability-detectionreverse-engineeringtriage
5.9k6882d ago