This is an overview of available tools for forensic investigators. Please click on the name of any tool for more details.
Note: This page has gotten too big and is being broken up. See:
- Category:Disk Imaging
- Tools:Data Recovery (including file carving)
- Tools:File Analysis
- Tools:Document Metadata Extraction
- Tools:Memory Imaging
- Tools:Network Forensics
- Tools:Logfile Analysis
- Category:Anti-forensics tools
- Category:Secure deletion
- 1 Disk Analysis Tools
- 2 Enterprise Tools (Proactive Forensics)
- 3 Forensics Live CDs
- 4 Personal Digital Device Tools
- 5 Other Tools
- 6 Telephone Scanners/War Dialers
Disk Analysis Tools
Hard Drive Firmware and Diagnostics Tools
- PC-3000 from DeepSpar Data Recovery Systems
- Macintosh Forensic Software by BlackBag Technologies, Inc.
- EMail Detective - Forensic Software Tool by Hot Pepper Technology, Inc
- ILook Investigator by Elliot Spencer and U.S. Dept of Treasury, Internal Revenue Service - Criminal Investigation (IRS)
- P2 Power Pack by Paraben
- DateDecoder by Live-Forensics
- A command line tool that decodes most encoded time/date stamps found on a windows system, and outputs the time/date in a human readable format.
- RecycleReader by Live-Forensics
- A command line tool that outputs the contents of the recycle bin on XP, Vista and Seven.
Open Source Tools
- A library for working with disk images. Currently AFFLIB supports raw, AFF, AFD, and EnCase file formats. Work to support segmented raw, iLook, and other formats is ongoing.
- Digital Forensics Framework (DFF)
- DFF is cross-platform and open-source, user and developers oriented. It provide many features and is very modular. Our goal is to provide a powerful framework to the forensic community, so people can use only one tool during the analysis. http://www.digital-forensic.org
- FTimes is a system baselining and evidence collection tool.
- Tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.
- A generic framework for binary file manipulation, it supports FAT12, FAT16, FAT32, ext2/ext3, Linux swap, MSDOS partition header, etc. Recognize file type. Able to find subfiles (hachoir-subfile).
- Web-based, database-backed forensic and log analysis GUI written in Python.
- Linux and Windows file carving program originally based on foremost.
NDA and scoped distribution tools
Enterprise Tools (Proactive Forensics)
Forensics Live CDs
- A Live CD built on top of Ubuntu (early version are built on top of Slackware). Latest "pre-release" has "forensics mode".
- DEFT Linux
- A Live CD built on top of Xubuntu with the best tools for computer forensics and incident response.
- It's a very light and fast live system created for the Computer Forensics specialists.
- The first live CD with AFF, dhash and Xplico.
- THE FARMER'S BOOT CD
- A Linux Live CD, designed and optimized for previewing data in a forensically sound manner. It contains a number of programs forensic practitioners can utilize to preview both Windows and Linux systems.
- FCCU Gnu/Linux Boot CD
- A Live CD built on top of Debian Live with a lot of tools with forensic purpose.
- Helix3 (Helix3 Pro)
- A Live CD built on top of Ubuntu with special tools for incident response and electronic discovery.
- Masterkey Linux
- A Linux Live CD built on top of Slackware featuring a wide variety of free and open source tools, focused on both Incident Response and Computer Forensic Examination.
- Recovery Is Possible
- A Linux Live CD with a number of recovery applications such as TestDisk, PhotoRec, etc.
- SAFE Boot Disk
- The first and only commercially available forensically sound Windows Boot disk.
- Includes built-in driver support, access to the NTFS file system and built-in software write blocking.
- SMART Linux
- Two Live CDs built on top of Slackware and Ubuntu. Includes SMART and other forensic tools.
Out of date Live CDs
- A FreeBSD based forensics Bootable ISO (includes Autopsy and Sleuth Kit).
Personal Digital Device Tools
Cell Phone Forensics
- Cellebrite UFED
- DataPilot Secure View
- GSM .XRY
- Fernico ZRT
- LogiCube CellDEK
- Oxygen Forensic Suite 2010
- Paraben's Device Seizure and Paraben's Device Seizure Toolbox
- Serial Port Monitoring
SIM Card Forensics
- Cellebrite UFED
- Paraben's SIM Card Seizure
- Computer Forensics Toolkit
- This is a collection of resources, most of which are informational, designed specifically to guide the beginner, often in a procedural sense.
- Live View
- Live View is a graphical forensics tool that creates a VMware virtual machine out of a dd disk image or physical disk.
- Microsoft Virtual PC
- VMware Player
- A free player for VMware virtual machines that will allow them to "play" on either Windows or Linux-based systems.
- VMware Server
- The free server product, for setting up/configuring/running VMware virtual machine.Important difference being that it can run 'headless', i.e. everything in background.
- Software for forensic analysis of internet resources (IP address, e-mail address, domain name, URL, e-mail headers, log files...)
- KDE's new cross-platform hex editor with features such as signature-matching
- Computer forensics software, data recovery software, hex editor, and disk editor from X-Ways.
- Live-Forensics software that reads windows files at specified offset and length and outputs results to the console.
Telephone Scanners/War Dialers
- PhoneSweep is a commercial grade multi-line wardialer used by many security auditors to run telephone line scans in their organizations. PhoneSweep Gold is the distributed-access add-on for PhoneSweep, for organizations that need to run scans remotely.