#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

Extracts and downloads Snap Map media by coordinates for OSINT, forensic analysis, and research. Supports metadata logging and bulk download.
Malware Configuration And Payload Extraction

Static analysis tool for investigating potentially malicious Microsoft Excel files, extracting metadata, macros, and embedded objects to aid digital…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Cross-platform registry browser for raw Windows registry files

helps visualize heap operations for pwn and debugging

ThePhish: an automated phishing email analysis tool

Automagically extract forensic timeline from volatile memory dump

Free hands-on digital forensics labs for students and faculty

Labs for Practical Malware Analysis & Triage

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Tool to extract the $UsnJrnl from an NTFS volume

Commandline low level file extractor for NTFS

Python tool that parses the NTFS $MFT to copy locked files during incident response, bypassing OS locks by reading raw disk locations. Supports…

The multi-platform memory acquisition tool.