This page pulls together a broad set of DFIR tools so you can jump straight to the official download or project page. Always verify hashes, signatures, licenses, and legal requirements before using any tool in an investigation.

Follow your organizations policies.

Please understand as well that these tools are not added as recommendations to use by the developer. The tools listed in this catalog were found by AI to be of revelance in digital forensics.

This filters all tool cards on this page by name, description, and tags.

Triage & Imaging

Disk imaging, quick triage, and evidence acquisition.

FTK Imager

Disk imaging & preview

Lightweight imaging and preview tool for acquiring forensic images, mounting them, and verifying hash values.

Platform: Windows • License: Free
Download FTK Imager →

Magnet ACQUIRE

Evidence acquisition

Tool for acquiring images from computers and some mobile devices, often used as an entry point for Magnet’s analysis stack.

Platform: Windows • License: Free (registration required)
Magnet ACQUIRE →

Guymager

Open-source imaging (Linux)

Fast, open-source forensic imager for Linux with support for multiple image formats and verification.

Platform: Linux • License: Open-source
Guymager Project →

Memory Forensics

RAM acquisition and deep analysis of live system artifacts.

Volatility 3

Memory forensics framework

Analyze memory dumps from Windows, Linux, and macOS to recover processes, drivers, network connections, and potential malware.

Platform: Cross-platform (Python) • License: Open-source
Volatility 3 on GitHub →

OSForensics RAM Imager

RAM acquisition

Capture physical memory from Windows systems for later analysis using Volatility and other frameworks.

Platform: Windows • License: Free tool
OSF Memory Imager →

Mobile & Device Forensics

iOS, Android, and unified logs / backup analysis.

iLEAPP

iOS Logs, Events, And Plist Parser

Parses iOS/iPadOS extractions and backups, surfacing logs, plists, notifications, and other artifacts into HTML/CSV reports.

Platform: Cross-platform (Python) • License: Open-source
iLEAPP on GitHub →

ALEAPP

Android Logs, Events, And Protobuf Parser

Companion to iLEAPP for Android devices, parsing logs, protobufs, and app data from extractions and backups.

Platform: Cross-platform (Python) • License: Open-source
ALEAPP on GitHub →

UFADE

iOS unified logs & backups

Uses pymobiledevice3 under the hood to create advanced iOS logical backups and extract unified logs for further analysis.

Platform: Windows, macOS, Linux • License: Open-source
UFADE on GitHub →

ALEX

Android Logical Extractor

ADB-based Android extraction utility supporting sdcard pulls, backups, logging, and optional on-the-fly artifacts like screenshots.

Platform: Windows, macOS, Linux • License: Open-source
ALEX on GitHub →

Arsenic Triage Tool

Consent-based iOS triage

Mobile triage tool focusing on quick, consent-based iOS investigations with targeted artifact analysis for on-scene use.

Platform: Windows, Apple Silicon • License: Free
Arsenic Triage Tool →

Forensic Suites & Platforms

Full-featured forensic environments and toolkits.

Autopsy

Digital forensics platform

Full GUI-based platform built on The Sleuth Kit for file system, artifacts, timeline, and media analysis.

Platform: Windows, Linux • License: Open-source
Download Autopsy →

Sleuth Kit

File system analysis toolkit

Command-line tools for detailed file system analysis, image parsing, and low-level artifact work.

Platform: Cross-platform • License: Open-source
Download Sleuth Kit →

Kali Linux

Security & forensics distro

Linux distribution packed with security, DFIR, and network analysis tools. Available as ISO, VM image, and WSL.

Platform: Linux, VM, WSL • License: Free
Get Kali Linux →

SANS SIFT Workstation

Incident response & forensics VM

Pre-built Linux workstation with a large collection of DFIR tools, tailored for incident response workflows.

Platform: VM (Ubuntu-based) • License: Free
SIFT Workstation →

Windows Artifact & Triage Tools

Registry, file system, and artifact parsers.

Eric Zimmerman Tools

Windows artifact parsing toolkit

Collection of tools (MFTECmd, AmCacheParser, LECmd, ShellBags Explorer, etc.) for deep Windows artifact analysis.

Platform: Windows • License: Free for DFIR use
Download EZ Tools →

KAPE

Windows artifact triage & collection

Rapid collection and parsing framework that uses modular targets and parsers to triage Windows systems quickly.

Platform: Windows • License: Free (EULA)
Get KAPE →

RegRipper

Registry hive parser

Classic Windows registry analysis tool that parses hives using plugins focused on forensic-relevant keys and values.

Platform: Windows, Perl • License: Open-source
RegRipper on GitHub →

Arsenal Image Mounter

Forensic image mounting

Mount forensic images as local disks, with options to expose virtual disk structures to tools and the OS.

Platform: Windows • License: Free / commercial
Arsenal Image Mounter →

Network Forensics, PCAP & Port Utilities

Packet capture, protocol analysis, network monitoring, and quick port lookups.

Wireshark

Network protocol analyzer

Widely used network analysis tool for inspecting live traffic and PCAP files, supporting hundreds of protocols.

Platform: Windows, macOS, Linux • License: Open-source
Download Wireshark →

NetworkMiner

Network artifact reconstruction

Parses PCAPs to extract files, credentials, sessions, and host information from captured network traffic.

Platform: Windows (Mono on Linux) • License: Free / Pro
NetworkMiner →

Zeek

Network security monitoring

Network security engine that converts traffic into rich logs, excellent for incident response and hunt operations.

Platform: Linux/Unix • License: Open-source
Get Zeek →

SpeedGuide Port Lookup

Common port reference

Database of common TCP/UDP ports and their associated services, useful when analyzing firewall logs and network captures.

Platform: Web • License: Free
SpeedGuide Ports →

TCPDump

CLI packet capture tool

Classic command-line packet analyzer used extensively on Linux/Unix systems for live capture and quick review.

Platform: Unix-like • License: Open-source
TCPDump →

TShark

Wireshark’s CLI interface

Command-line counterpart to Wireshark for scripting, automation, and headless packet capture and analysis.

Platform: Cross-platform • License: Open-source
TShark Docs →

Browser & Cloud Forensics

Web history, cloud app, and SaaS artifact analysis.

Hindsight

Chrome browser forensics

Parses Chrome/Chromium history and artifacts to reconstruct user activity, including URLs, downloads, and session data.

Platform: Cross-platform (Python) • License: Open-source
Hindsight on GitHub →

Browser History Viewer / NirSoft Tools

Multi-browser history viewers

Tools that read browser history, cache, and cookies from multiple browsers to support timeline reconstruction.

Platform: Windows • License: Freeware
NirSoft Browser Tools →

Reverse Engineering & Malware DFIR

Static and dynamic analysis helpers.

Ghidra

Software reverse engineering suite

Feature-rich framework for reverse engineering binaries with a powerful decompiler and scripting support.

Platform: Cross-platform (Java) • License: Open-source
Download Ghidra →

CAPA

Malware capability detector

Analyzes binaries to detect capabilities (e.g., keylogging, C2, persistence) using rules, rather than signatures.

Platform: Cross-platform • License: Open-source
CAPA on GitHub →

FLOSS

Obfuscated string extraction

Extracts and deobfuscates strings from malware, helping you quickly see C2 URLs, commands, and configuration.

Platform: Cross-platform • License: Open-source
FLOSS on GitHub →

Password & Hash Tools

Cracking, auditing, and hash analysis.

Hashcat

GPU-accelerated password cracker

High-performance password recovery tool supporting many hash types and attack modes, widely used in auditing.

Platform: Windows, Linux • License: Open-source
Download Hashcat →

John the Ripper

Password cracking toolkit

Classic password auditing tool that supports a wide range of hash formats and cracking strategies.

Platform: Cross-platform • License: Open-source / Pro
John the Ripper →

Incident Response & Endpoint Platforms

Endpoint triage, hunting, and fleet visibility.

Velociraptor

Endpoint visibility & DFIR

Open-source platform for collecting artifacts at scale, hunting, and performing remote DFIR operations.

Platform: Cross-platform • License: Open-source
Velociraptor →

OSQuery

Endpoint SQL-based visibility

Turns endpoints into SQL-queryable data sources, useful for rapid IR questions across many systems.

Platform: Windows, macOS, Linux • License: Open-source
OSQuery →

Sysinternals Suite

Windows internals toolkit

Comprehensive set of Windows utilities (ProcMon, ProcExp, Autoruns, etc.) essential for IR and troubleshooting.

Platform: Windows • License: Free
Sysinternals Suite →

Linux DFIR & Timeline Tools

Logs, timelines, and post-mortem analysis.

Plaso (log2timeline)

Automated super timeline creation

Creates super timelines from many log sources and artifacts, forming the backbone of time-based investigations.

Platform: Cross-platform • License: Open-source
Plaso on GitHub →

Timesketch

Collaborative timeline analysis

Web-based tool used to explore and annotate forensic timelines, often paired with Plaso-generated data.

Platform: Web/Server • License: Open-source
Timesketch on GitHub →

3D, Photo & Photography Tools

Photogrammetry, point clouds, cleanup, and camera training helpers.

3DF Zephyr Photogrammetry Suite

3D reconstruction from photos

Photogrammetry software for turning photos into 3D models, useful for scene reconstruction and documentation.

Platform: Windows • License: Free/Commercial
3DF Zephyr →

CloudCompare

Point cloud & 3D mesh tool

Open-source 3D point cloud and mesh processing tool, useful for analyzing scans and model comparison.

Platform: Cross-platform • License: Open-source
CloudCompare →

Cleanup.pictures

Object & artifact removal

Web-based tool for removing unwanted objects from images. Helpful for report graphics and presentation-ready visuals.

Platform: Web • License: Free/Commercial
Cleanup Pictures →

CameraFRASE

Camera forensics utility

Tooling from CameraForensics to assist with camera-related investigation workflows.

Platform: Web • License: Free/Commercial
CameraFRASE →

CameraSim DSLR Simulator

Camera behavior simulator

DSLR behavior simulator that helps visualize how camera settings affect images—a useful teaching aid when explaining photo evidence.

Platform: Web • License: Free/Commercial
CameraSim →

Cutout Pro Background Remover

AI background removal

AI-based background remover that can quickly isolate subjects for presentations, timelines, or training material.

Platform: Web • License: Free/Commercial
Cutout Pro →

Data, Encoding & File Utilities

Encoding, metadata, and database helpers.

ASCII Converter

Character ↔ code conversions

Quick conversion between characters and ASCII codes when examining data fragments or low-level artifacts.

Platform: Web • License: Free
ASCII Converter →

Dcode Forensic Decoding Suite

Date, time & data decoders

A long-standing decoding suite for converting hex, timestamps, binary data, and other encodings common in DFIR.

Platform: Windows • License: Free/Commercial
Dcode Suite →

SQLite Database Browser

SQL database viewer/editor

GUI viewer and editor for SQLite databases, which underlie many application and mobile artifacts.

Platform: Cross-platform • License: Open-source
DB Browser for SQLite →

EXIFTool

Metadata extraction utility

Powerful command-line utility for reading and writing metadata in a wide range of file formats (images, docs, etc.).

Platform: Cross-platform • License: Open-source
EXIFTool →

LinangData EXIF Reader

Browser-based EXIF viewer

Web EXIF viewer for quickly inspecting metadata without installing local tools— handy for quick triage.

Platform: Web • License: Free
LinangData EXIF Reader →

PDFEscape Online PDF Editor

PDF editing & annotation

Online editor for redacting, annotating, and modifying PDFs when preparing case reports or exhibits.

Platform: Web • License: Free/Commercial
PDFEscape →

Design, Reporting & Visuals

Presentations, dashboards, and report-ready visuals.

Canva Templates Library

Templates for slides & documents

Large library of templates for reports, presentations, and visual explainers around your DFIR findings.

Platform: Web • License: Free/Commercial
Canva Templates →

Flourish

Interactive data visualization

Tool for building interactive charts, maps, and visualizations that can help communicate forensic timelines and relationships.

Platform: Web • License: Free/Commercial
Flourish Studio →

Email & Header Analysis

Email tracing, headers, and deliverability checks.

MXToolbox Email Header Analyzer

Header parsing & routing

Parses email headers to show routing details, delays, and potential issues, useful in phishing and fraud investigations.

Platform: Web • License: Free/Commercial
MXToolbox Header Analyzer →

Verifalia Email Validator

Email validity checks

Validates whether email addresses are syntactically valid and deliverable— helpful for victim/suspect contact data.

Platform: Web • License: Free/Commercial
Verifalia →

Browser, Capture & Scraping Tools

Screenshots, web capture, scraping, and media grabbers.

CopyFish OCR

On-screen OCR in the browser

Browser extension that performs OCR on selected screen areas, useful for grabbing text from images and web apps.

Platform: Chrome extension • License: Free
CopyFish OCR →

DumpItBlue+

Screenshot & capture helper

Screenshot tool focused on capturing web content for documentation and evidence.

Platform: Chrome extension • License: Free
DumpItBlue+ →

Nimbus Screenshot

Browser screenshots & recording

Capture entire pages, regions, or videos from the browser for later reference or inclusion in case files.

Platform: Browser extension • License: Free/Commercial
Nimbus Screenshot →

Greenshot

Desktop screenshot tool

Lightweight screenshot utility for Windows that supports annotations and quick exports.

Platform: Windows • License: Free/Open-source
Greenshot →

HTTrack Website Copier

Website mirroring

Downloads sites for offline browsing and preservation; useful when you need a local copy of web content.

Platform: Windows, Linux • License: Open-source
HTTrack →

OBS Studio

Screen & video recording

Open-source screen recording and streaming tool often used to capture volatile or interactive evidence.

Platform: Windows, macOS, Linux • License: Open-source
OBS Studio →

Online Video Downloader

Web video capture

Online service that converts and downloads videos from popular platforms for evidence preservation (use legally).

Platform: Web • License: Free
Online Video Downloader →

Web to PDF Converter

Page capture to PDF

Converts full web pages into PDFs for archiving and including in case documentation.

Platform: Web • License: Free
Web2PDF Converter →

Windows Screen Recorder Pro

Windows 10 screen recorder

Microsoft Store-based screen recorder for capturing on-screen actions and volatile states on Windows systems.

Platform: Windows • License: Free/Store
Screen Recorder Pro →

Device Specs & IMEI Lookups

Handset identification, specs, and IMEI-based lookups.

GSM Arena Device Database

Phone specs & models

Comprehensive database of mobile device specifications, generations, and variants.

Platform: Web • License: Free
GSM Arena →

IMEI Check

IMEI lookups

Online IMEI checker useful for validating device identifiers during mobile investigations.

Platform: Web • License: Free/Commercial
IMEI Check →

IMEI.info

Device information from IMEI

IMEI-based device lookup service for retrieving manufacturer, model, and sometimes basic status information.

Platform: Web • License: Free/Commercial
IMEI.info →

PhoneScoop

Phone model lookups

Phone directory and spec database that can assist in identifying handset capabilities and release timelines.

Platform: Web • License: Free
PhoneScoop →

Additional IR / DFIR Tool Collections

Suites, collections, and curated tool lists.

Breakpoint Forensics Tools

Windows & DFIR utilities

Collection of DFIR tools and utilities for artifact parsing and investigation tasks.

Platform: Windows • License: Free/Commercial
Breakpoint Tools →

CyberTriage

IR triage & investigation platform

Incident response and triage platform for quickly assessing compromised systems.

Platform: Windows • License: Commercial / Eval
CyberTriage Eval →

CyberTriage Product Page →

Technitium MAC Address Changer

Network adapter MAC tool

Utility for viewing and changing MAC addresses on Windows adapters—useful in lab or testing environments.

Platform: Windows • License: Free
Technitium MAC Changer →

FireEye Redline

Endpoint triage & analysis

Classic endpoint triage tool that collects system information, memory data, and indicators for analysis.

Platform: Windows • License: Free
Redline Download →

INV Network Free DFIR Tools

Free forensic utilities

Hub of free forensic tools and resources maintained by INV Network.

Platform: Various • License: Free
INV DFIR Tools →

Arsenal Recon Downloads

Forensic tools & utilities

Download center for Arsenal Recon utilities, including powerful imaging and mounting tools.

Platform: Windows • License: Free/Commercial
Arsenal Recon Downloads →

Kali Linux Tools List

Catalog of Kali tools

Online index of all tools included with Kali Linux, organized by category and function.

Platform: Web • License: Free
Kali Tools List →

Monolith Forensics Free Tools

Curated tool collection

Collection of free forensic utilities and scripts curated by Monolith Forensics.

Platform: Various • License: Free
Monolith Free Tools →

Password & Hash Resources

Online hash lookup and cracking references.

CrackStation Hash Lookup

Online hash cracking database

Online service for looking up common hashed passwords via a large precomputed table— useful during password investigations.

Platform: Web • License: Free
CrackStation →

Time, Date & Misc Utilities

Time zones, math helpers, and general utilities.

SavvyTime UTC Converter

Time zone conversions

Convert timestamps across time zones, particularly helpful when correlating logs from different regions.

Platform: Web • License: Free
SavvyTime Converter →

World Clock Time Zone Converter

Multi-time-zone comparison

Compare multiple time zones at once, simplifying cross-region case timelines.

Platform: Web • License: Free
TimeAndDate Converter →

WhatTimeIsIt

Simple reference clock

Minimal clock site for quickly confirming current time without OS clutter.

Platform: Web • License: Free
WhatTimeIsIt.com →

Speed Distance Time Calculator

Motion math helper

Calculator for solving speed, distance, and time problems—occasionally useful for reconstructions and vehicle cases.

Platform: Web • License: Free
Speed/Distance/Time Calculator →

Blockchain Explorer

Cryptocurrency transaction viewer

High-level blockchain explorer for reviewing cryptocurrency addresses and transactions in crypto-related cases.

Platform: Web • License: Free
Blockchain Explorer →

TextEm

Web-based SMS sender

Web interface for sending SMS via carriers—occasionally referenced in investigations or testing scenarios.

Platform: Web • License: Free
TextEm →

AlternativeTo

Software alternative directory

Directory for finding alternative software when specific tools are not allowed, licensed, or available in your environment.

Platform: Web • License: Free
AlternativeTo →

TinyWow

Online utility toolbox

Collection of small web utilities for file conversion, PDF manipulation, and more.

Platform: Web • License: Free
TinyWow →

Utility & Misc Tools

Data wrangling, decoding, and helper utilities.

CyberChef

Data transformation “Swiss Army knife”

Web and local tool for encoding/decoding, parsing, and analyzing data used in DFIR, malware analysis, and OSINT.

Platform: Web, local build • License: Open-source
CyberChef on GitHub →

Built as part of the 4nsic Zone project. Connect on LinkedIn: Katelyn Rogers

Always verify tool hashes/signatures and follow your organization’s policies and local laws.