

Distributed & real time digital forensics at the speed of the cloud

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…



Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Free hands-on digital forensics labs for students and faculty

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

A list of cyber-chef recipes and curated links

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux