ENNAENNA
🔬

Digital Forensics

23 tools indexed

Digital forensics tools for disk imaging, memory analysis, file carving, log timeline reconstruction, and evidence preservation. Used by incident responders, law enforcement, and security analysts to investigate breaches and recover digital evidence.

Volatility 3

Python
Featured

Advanced memory forensics framework. Extracts artifacts from RAM dumps - processes, network connections, registry.

memoryram-dumpartifact-extractionincident-response
4.1k64827d ago

Autopsy

Java

Digital forensics platform with GUI. Disk image analysis, timeline analysis, keyword search, hash filtering.

disk-forensicsguitimelinefile-carving
3.1k6591mo ago

Ghidra

Java
Featured

NSA's reverse engineering framework. Disassembly, decompilation, graphing, and scripting for binary analysis.

reverse-engineeringdecompilerbinary-analysisnsa
67.7k7.4k24d ago

Binwalk

Python

Firmware analysis tool. Searches binary images for embedded files, executables, and file systems.

firmwarebinaryextractionembedded
13.9k1.8k1mo ago

YARA

C
Featured

Pattern matching swiss knife for malware researchers. Create rules to identify and classify malware samples.

malwarepattern-matchingrulesclassification
9.6k1.6k3mo ago

Velociraptor

Go
Featured

Endpoint visibility and collection tool. Hunt for artifacts across thousands of endpoints simultaneously.

endpointhuntingdfirartifact-collection
3.9k60923d ago

Plaso (log2timeline)

Python

Super timeline creation engine. Extracts timestamps from multiple forensic artifact sources into a single timeline.

timelinelog-analysisartifactsuper-timeline
2.1k41123d ago

Radare2

C

Portable reversing framework. Disassembly, debugging, analysis, patching, and scripting in a single CLI.

reverse-engineeringdisassemblerdebuggerscripting
23.5k3.2k24d ago

Cutter

C++

GUI for Radare2. Makes reverse engineering accessible with graphs, decompiler, and hex editor built in.

reverse-engineeringguiradare2decompiler
18.7k1.4k25d ago

The Sleuth Kit

C

Collection of command-line tools for forensic analysis of disk images and file systems.

disk-forensicsfile-systemanalysisimaging
3.1k68723d ago

CyLR

C#

Live response collection tool for quickly gathering forensic artifacts from hosts during incident response.

incident-responseartifact-collectionlive-responsetriage
723953y ago

Chainsaw

Rust

Rapidly search and hunt through Windows forensic artifacts like event logs, MFT, and Shimcache using Sigma rules.

windows-forensicsevent-logssigma-rulesthreat-hunting
3.5k29723d ago

Hayabusa

Rust

Windows event log fast forensics timeline generator and threat hunting tool with built-in Sigma rule support.

windows-eventstimelinesigmadfir
3.1k26426d ago

oletools

Python

Python tools for analyzing OLE and MS Office files - detect VBA macros, embedded objects, and malicious content.

office-analysisvba-macrosolemalware-analysis
3.3k6003mo ago

PE-sieve

C++

Scans running processes for suspicious in-memory modifications including hollowing, hooking, and code injection.

process-scanningmemory-forensicscode-injectionmalware-detection
3.6k4711mo ago

capa

Python

Automatically identify capabilities in executable files - detects techniques like persistence, C2, and anti-analysis.

malware-analysiscapability-detectionreverse-engineeringtriage
6.0k69623d ago

RegRipper

Perl

Windows registry forensic parser. Extracts and decodes forensic artifacts from registry hives with extensible plugins.

registrywindows-forensicsartifact-extractiondfir
6991491y ago

bulk_extractor

C++

High-performance forensic data carver. Extracts email addresses, URLs, credit cards, and other artifacts from disk images at speed.

data-carvingdisk-forensicsemail-extractionparallel
1.4k2183mo ago

Timesketch

Python

Google's collaborative forensic timeline analysis platform for organizing and annotating investigation events.

timelineforensicsdfircollaboration
3.3k65028d ago

Depix

Python

Recover plaintext from pixelized screenshots using De Bruijn sequence matching.

forensicsdepixelizeimagerecovery
4.5k3611mo ago

usbrip

Python

Track USB device connection history and generate forensic artifacts on Linux.

usbforensicstrackingartifacts
1.2k1133y ago

Fibratus

Go

Windows kernel event tracing and threat detection tool. Captures process, file, registry, network, and driver events in real-time.

etwkernel-tracingwindows-forensicsthreat-hunting
2.4k20823d ago

Cowrie

Python

Medium-interaction SSH and Telnet honeypot. Logs brute force attacks, shell interactions, and malware downloads.

honeypotsshtelnetthreat-intelligence
6.3k1.0k1mo ago