DfirtrackDFIRTrack - The Incident Response Tracking Application
IpedIPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by law enforcement or in a corporate investigation by private examiners.
ThehiveTheHive: a Scalable, Open Source and Free Security Incident Response Platform
LimeaideA python application designed to remotely dump RAM of a Linux client and create a volatility profile for later analysis on your local host.
C Aff4An AFF4 C++ implementation.
TcpflowTCP/IP packet demultiplexer. Download from:
BeagleBeagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Forensic ToolsCIRCL system forensic tools or a jumble of tools to support forensic
Artifacts📇 Digital Forensics Artifact Repository (forensicanalysis edition)
WhatfilesLog what files are accessed by any Linux process
MemlabsEducational, CTF-styled labs for individuals interested in Memory Forensics
CortexCortex: a Powerful Observable Analysis and Active Response Engine
KuiperDigital Forensics Investigation Platform
hotolotidocumentation, scripts, tools related to Zena Forensics (http://blog.digital-forensics.it)
CASECyber-investigation Analysis Standard Expression (CASE) Ontology
artifactcollector🚨 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system
catalystCatalyst is an open source SOAR system that helps to automate alert handling and incident response processes
pyaff4The Python implementation of the AFF4 standard.
ForensicsToolsA list of free and open forensics analysis tools and other resources
Red-Rabbit-V4The Red Rabbit project is just what a hacker needs for everyday automation. Red Rabbit unlike most frameworks out there does not automate other peoples tools like the aircrack suite or the wifite framework, it rather has its own code and is raw source with over 270+ options. This framework might just be your everyday key to your workflow
MemProcFS-AnalyzerMemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
INDXRipperCarve file metadata from NTFS index ($I30) attributes
ThePhishThePhish: an automated phishing email analysis tool