#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

iOS/macOS Research Swiss Army Knife

privacy-first, open-source and free idevice management tool written in Rust and Qt

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Rapidly Search and Hunt through Windows Forensic Artefacts

Dshell is a network forensic analysis framework.

You didn't think I'd go and leave the blue team out, right?

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

A Linux version of the ProcDump Sysinternals tool

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

reverse engineering Gemini's SynthID detection

Graphical forensic toolkit for parsing, decrypting, and extracting WhatsApp data from Android and iOS devices, including Google Drive and iCloud…

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Security sensor for realtime threat detection and protection

Your Everyday Threat Intelligence

Recovers lost partitions and repairs boot sectors; carves 480+ file formats from damaged disks and filesystems for data recovery and forensic use.