DFIR Tools

FeaturedToolLicenseCategoryKeywords
ADF DEI PRO Field TabletProprietaryTriagetablet, mobile
ADF The ADF Cloud PlatformProprietaryReportinglicense, cloud, management
ADF Digital Evidence Investigator (DEI)ProprietarySuitetimeline, triage
ADF Digital Evidence Investigator PRO (DEI PRO)ProprietarySuitetriage, media exploitation
ADF Mobile Device Investigator (MDI)ProprietarySuitemobile, analysis
ADF MDI Field TabletProprietarySuitetriage, mobile, tablet
ADF Triage-G2 (TG2)ProprietaryTriagemedia exploitation
ADF Triage-G2 PRO (TG2 PRO)ProprietaryTriagemobile, media exploitation, triage
ADF Triage-Investigator (TINV)ProprietaryTriagetriage, reporting, analysis
ADF Triage-Investigator PRO (TINV PRO)ProprietaryTriagetriage, reporting, analysis
Arsenal Recon Gmail URL DecoderFreeUser Createdemail, gmail, URL
Arsenal Recon Cybergate Log DecryptFreeEncryptionlog, decrypt
Arsenal Recon Hive ReconProprietaryAnalysisregistry, hbin, hibernation, syscache, userassist
Arsenal Recond Hibernation ReconProprietaryAnalysishibernation
Arsenal Image MounterProprietaryImage mounting
Arsenal Image MounterFreeImage mounting
Arsenal Recon NetWire Log DecoderFreeAnalysislog, netwire
Arsenal Recon Sdba ParserFreeMemory sdba
Arsenal Recon Backstage ParserFreeUser CreatedMS Office, BackstageinAppNavCache
Arsenal Recon ODC ReconProprietaryUser CreatedMS Office, ODC
Arsenal Recon HBIN ReconProprietaryAnalysisHBIN, registry
Arsenal Recon Registry ReconProprietaryAnalysisRegistry
BasisTech RosetteProprietaryTextlinguistics, language, text
BasisTech AutopsyFreeSuiteforensic analysis
BasisTech KonasearchProprietaryTextlinguistics, language, text
BasisTech Cyber TriageProprietaryIRtriage, endpoints, threat, intrusion
Belkasoft Remote AcquistionProprietaryAcquisitionremote, ram, imaging,
Belkasoft Ram CapturerFreeAcquisitionmemory dump, ram, imaging
Belkasoft Evidence Center XProprietarySuiteforensic analysis
Belkasoft BELKAS21ProprietarySuiteforensic analysis
Belkasoft Incident InvestigationsProprietaryIRforensic analysis
Belkasoft TriageProprietaryTriagetriage
Forensic NotesProprietaryReportingreport writing, documentation
Magnet AXIOM CyberProprietaryIRforensic analysis
Magnet AQUIREFreeAcquisitionmobile, imaging
Magnet Custom Artifact GeneratorFreeAnalysisartifacts
Magnet AUTOMATE ProprietaryReportingCase management
Magnet AUTOMATE ENTERPRISEProprietaryReportingCase management
Magnet Web Page SaverFreeAnalysisInternet, browser
Magnet ATLASProprietaryReportingCase management
Magnet Apple Warrant Return AssistantFreeReportingCase management
Magnet DVR EXAMINERProprietaryUnique DevicesDVR, analysis
Magnet Encrypted Disk DetectorFreeEncryptionencryption detection
Magnet AXIOM Wordlist GeneratorFreeEncryptionpassword, decryption
Magnet Hash Sets ManagerFreeHashHash set management
Magnet DumpIt for WindowsFreeMemorymemory, dump, Windows
Magnet Dumpit-linuxFreeMemorymemory, dump, Linux
Magnet Process CaptureFreeMemorymemory, imaging
Magnet RAM CaptureFreeMemoryRAM, memory, imaging
Magnet RESPONSEFreeIRRAM, endpoint, collection, acquisition
Magnet SHIELDFreeReportingreport writing, documentation
Magnet REVIEWProprietaryReportingcase review, management
Magnet AXIOM ProprietarySuiteforensic analysis
Magnet IGNITEProprietaryIRtriage, endpoints, threat, intrusion
Magnet OUTRIDERProprietaryTriagetriage
Magnet App SimulatorFreeVirtualizationsimulator
Eric ZimmermanAmcacheParserFreeAnalysisamcache, artifact
Eric ZimmermanAppCompatCacheParserFreeAnalysisappcopatcache, artifact
Eric ZimmermanbstringsFreeAnalysisregex, search
CellebriteCellebrite CommanderProprietaryReportingCase management
CellebriteCellebrite Digital CollectorProprietaryAcquisitiontriage, imaging
CellebriteCellebrite Endpoint InspectorProprietaryIRendpoint, collection
CellebriteCellebrite FrontlinerProprietaryReportingreport writing, documentation
CellebriteCellebrite GuardianProprietaryReportingCase management
CellebriteCellebrite InspectorProprietaryAnalysissocial media collection, cloud, Internet
CellebriteCellebrite OSINT SolutionsProprietaryOSINT
CellebriteCellebrite PathfinderProprietaryReportingCase management
CellebriteCellebrite Physical AnalyzerProprietarySuiteforensic analysis
CellebriteCellebrite ReaderProprietaryReportingCase management
CellebriteCellebrite ResponderProprietaryAcquisitionreport writing, documentation
CellebriteCellebrite UFEDProprietarySuiteforensic analysis
CellebriteCellebrite UFED CloudProprietaryAcquisitionsocial media collection, cloud, Internet
Eric ZimmermanEvtxECmdFreeAnalysisevtxecmd, log
ExterroExterro Forensic ToolKit (FTK)ProprietarySuiteforensic analysis
ExterroExterro FTK CentralProprietarySuiteforensic analysis
ExterroExterro FTK ConnectProprietaryReportingCase management
ExterroExterro FTK EnterpriseProprietaryEnterpriseforensic analysis
ExterroExterro FTK ImagerFreeAcquisitionimaging, image mounting
Eric ZimmermanEZViewerFreeAnalysisfile viewer
Eric ZimmermanGet-ZimmermanToolsFreeMiscmisc
Eric ZimmermanHasherFreeHashhashing
Eric ZimmermaniisGeoLocateFreeAnalysisgeolocation
Eric ZimmermanJLECmdFreeAnalysisJLECmd, artifact
Eric ZimmermanJumpList ExplorerFreeAnalysisjumplist, artifact
Eric ZimmermanKAPEFreeSuiteforensic analysis
Eric ZimmermanLECmdFreeAnalysisLNK, artifact
Eric ZimmermanMFTECmdFreeAnalysisMFT, artifact
Eric ZimmermanMFTExplorerFreeAnalysisMFT, artifact
OpenTextOpenText EnCase Endpoint InvestigatorProprietaryIRendpoint, collection
OpenTextOpenText Encase ForensicProprietarySuiteforensic analysis
OpenTextOpenText EnCase Mobile InvestigatorProprietarySuitemobile, forensic analysis
OpenTextOpenText Tableau ForensicProprietaryAcquisitionwrite blocker, imaging
Oxygen ForensicsOxygen Forensic Cable KitProprietaryHardwarehardware
Oxygen ForensicssOxygen Forensics DetectiveProprietarySuiteforensic analysis
Oxygen Forensics Detective NetworkProprietaryReportinglicense, cloud, management
Oxygen ForensicssOxygen Forensics KITProprietaryAcquisitionmobile, extraction
Paraben CorporationParaben Corporation E3 ProprietarySuiteforensic analysis
Paraben CorporationParaben Corporation E3 Remote ImagerProprietaryAcquisitionremote, imaging
Paraben CorporationParaben Corporation E3: ViewProprietaryReportingCase management
Eric ZimmermanPECmdFreeAnalysisprefetch, artifact
Eric ZimmermanRBCmdFreeAnalysisrecyclebincache, artifact
Eric ZimmermanRecentFileCacheParserFreeAnalysisrecentfilecache, artifact
Eric ZimmermanRECmdFreeAnalysisregistry
Eric ZimmermanRegistry ExplorerFreeAnalysisregistry
Eric ZimmermanRLAFreeAnalysistransaction logs, registry
SANSSANS SIFT WorkstationFreeSuiteforensic analysis
Eric ZimmermanSBECmdFreeAnalysisshellbags, artifact
Eric ZimmermanSDB ExplorerFreeAnalysisshim database, artifact
Eric ZimmermanShellBags ExplorerFreeAnalysisshellbags, artifact
Eric ZimmermanSQLECmdFreeAnalysisSQLite
Eric ZimmermanSrumECmdFreeAnalysisSRUDB, artifact
Eric ZimmermanSumECmdFreeAnalysisMS user access logs
Eric ZimmermanTimeAppFreeReportingcurrent time
Eric ZimmermanTimeline ExplorerFreeReportingcsv xlsx viewer
Eric ZimmermanVSCMountFreeVirtualizationmount, vsc, virtual machine
Eric ZimmermanWxTCmdFreeReportingWindows 10 timeline database, artifact
X-Ways ForensicsX-Ways ForensicsProprietarySuiteforensic analysis
X-Ways ForensicsX-Ways ImagerProprietaryAcquisitionimaging
X-Ways ForensicsX-Ways InvestigatorProprietarySuiteforensic analysis
X-Ways ForensicsX-Ways WinHexProprietarySuiteforensic analysis
Eric ZimmermanXWFIMFreeMiscmisc
Stark4n6SQLiteWalkerFreeAnalysisSQLite, database