awesome-forensics icon indicating copy to clipboard operation
awesome-forensics copied to clipboard

A curated list of awesome forensic analysis tools and resources

Awesome Forensics

Awesome Link Status

A curated list of awesome free (mostly open source) forensic analysis tools and resources.

  • Awesome Forensics
  • Collections
  • Tools
    • Distributions
    • Frameworks
    • Live forensics
    • Imageing
    • Carving
    • Memory Forensics
    • Network Forensics
    • Windows Artifacts
    • OS X Forensics
    • Internet Artifacts
    • Hex Editors
    • Binary Converter
    • File Grammars
    • Disk image handling
    • Decryption
  • Learn Forensics
    • CTFs
  • Resources
    • File System Corpora
    • Twitter
    • Blogs
    • Other
  • Related Awesome Lists
  • Contributing

Collections

Tools

Distributions

  • deft - Linux distribution for forensic analysis

Frameworks

  • dff - Forensic framework
  • PowerForensics - PowerForensics is a framework for live disk forensic analysis
  • The Sleuth Kit - Tools for low level forensic analysis

Live forensics

  • grr - GRR Rapid Response: remote live forensics for incident response
  • mig - Distributed & real time digital forensics at the speed of the cloud

Imageing

  • dc3dd - Improved version of dd
  • dcfldd - Different improved version of dd (this version has some bugs!, another version is on github adulau/dcfldd)
  • FTK Imager - Free imageing tool for windows
  • Guymager - Open source version for disk imageing on linux systems

Carving

more at Malware Analysis List

  • bstrings - Improved strings utility
  • bulk_extractor - Extracts informations like email adresses, creditscard numbers and histrograms of disk images
  • floss - Static analysis tool to automatically deobfuscate strings from malware binaries
  • photorec - File carving tool

Memory Forensics

more at Malware Analysis List

Network Forensics

more at Malware Analysis List, Forensicswiki's Tool List, awesome-pcaptools and Wireshark Tool and Script List

  • SiLK Tools - SiLK is a suite of network traffic collection and analysis tools
  • Wireshark - The network traffic analysis tool

Windows Artifacts

more at Malware Analysis List

OS X Forensics

Internet Artifacts

  • hindsight - Internet history forensics for Google Chrome/Chromium

Hex Editors

  • 0xED - Native hex editor for OS X
  • Hexinator - Windows Version of Synalyze It!
  • HxD - Small, fast hex editor for Windows
  • iBored - Cross platform, sektor based hex editor
  • Synalyze It! - Hex editor with templates for binary analysis
  • wxHex Editor - Cross platform editor with file comparison

Binary Converter

  • CyberChef - The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
  • DateDecode - Convert binary data into differnt kinds of date formats

File Grammars

Disk image handling

  • aff4 - AFF4 is an alternative, fast file format
  • libewf - Libewf is a library and some tools to access the Expert Witness Compression Format (EWF, E01)
  • xmount - Convert between different disk image formats

Decryption

Learn forensics

CTFs

Resources

File System Corpora

Twitter

Blogs

  • thisweekin4n6.wordpress.com - Weekly updates for forensics

Other

Related Awesome Lists

Contributing

Pull requests and issues with suggestions are welcome!