Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

3 Commits
Β 
Β 

Repository files navigation

πŸ›‘οΈ DFIR Tools Collection

A curated collection of Digital Forensics & Incident Response (DFIR) tools used for forensic investigation, malware analysis, incident response, memory forensics, disk analysis, and triage.

This toolkit includes tools from my DFIR environment + recommended industry-standard DFIR tools.


πŸ“Œ Table of Contents


Overview

This toolkit is designed for:

  • Digital forensic investigations
  • Malware and incident response
  • Live system triage
  • File, memory, registry, and network analysis
  • DFIR learning and CTF challenges

Disk & File System Forensics

πŸ”Ή Sleuth Kit

Open-source forensic suite used to analyze partitions, recovered files, timestamps, and disk structures.

πŸ”Ή Disk Analysis

Category containing tools for examining disk images (E01, RAW, VHD), partitions, file carving, etc.

πŸ”Ή Autopsy (Recommended)

GUI forensic platform for analyzing digital media, recovering deleted files, and generating reports.

πŸ”Ή FTK Imager (Recommended)

Used for creating forensic images and previewing disk contents without altering evidence.


Memory Forensics

πŸ”Ή Memory Analysis

May include Volatility, Volatility3, or Rekall for analyzing memory dumps.

πŸ”Ή Volatility / Volatility 3 (Recommended)

Industry-standard RAM forensics tool.
Finds:

  • Processes
  • Injected code
  • Network connections
  • DLLs
  • Malware in memory

πŸ”Ή DumpIt / WinPMEM (Recommended)

Tools used to acquire RAM images from live systems.


Malware Analysis

πŸ”Ή Malware Analysis Folder

General tools for analyzing malware behavior.

πŸ”Ή PEStudio

Static analysis of executables to reveal suspicious indicators.

πŸ”Ή CAPA (Mandiant) (Recommended)

Automatically identifies malware capabilities.

πŸ”Ή x64dbg / OllyDbg (Recommended)

Debuggers for reverse engineering malware.

πŸ”Ή Ghidra (Recommended)

NSA’s reverse engineering suite for binary analysis.

πŸ”Ή CyberChef (Recommended)

Multi-purpose tool for decoding, deobfuscation, encryption, and data transformations.


Network Forensics

πŸ”Ή Network Analysis

Category for traffic analysis tools.

πŸ”Ή Wireshark (Recommended)

Most widely used tool for investigating PCAP files.

πŸ”Ή Tshark

Command-line packet analyzer.

πŸ”Ή Zeek (Recommended)

Generates metadata logs from network traffic (very useful for IR and timeline analysis).

πŸ”Ή Nmap

Port and service scanning, OS fingerprinting, and vulnerability discovery.


Log & Registry Analysis

πŸ”Ή LogFileParser

Parses log files like Windows event logs, firewall logs, proxy logs, etc.

πŸ”Ή Registry Analysis

Registry parsing tools such as:

  • RegRipper
  • Registry Explorer

πŸ”Ή Sysinternals Suite

Includes:

  • Autoruns – persistence detection
  • Process Explorer – process investigation
  • Procmon – event tracing
  • TCPView – network connection monitoring

Browser & Email Forensics

πŸ”Ή Browser Analysis

Tools for viewing:

  • History
  • Cookies
  • Cache
  • Autofill
  • Download records

πŸ”Ή Email Analysis

Supports PST, OST, MBOX, EML formats for email forensic investigations.

πŸ”Ή ExifTool

Extracts metadata (EXIF, GPS, timestamps) from:

  • Images
  • PDFs
  • Videos
  • Documents

Triage & Incident Response

πŸ”Ή EZ Tools (Eric Zimmerman Tools)

Popular set of Windows forensic tools:

  • KAPE
  • Registry Explorer
  • JumpList Explorer
  • ShellBags Explorer
  • USB Detective

πŸ”Ή Aurora

Rapid incident response triage tool.

πŸ”Ή Data Triaging

Tools that quickly scan systems for malicious files, processes, and persistence mechanisms.

πŸ”Ή PersistenceSniper

Detects hidden or abnormal persistence across:

  • Run keys
  • Services
  • Scheduled tasks
  • WMI

Data Recovery

πŸ”Ή Recovery Data

Tools for restoring deleted partitions, lost files, and corrupt storage devices.

πŸ”Ή PhotoRec / TestDisk (Recommended)

Most widely used open-source recovery utilities.


Hex Editors & Binary Tools

πŸ”Ή HxD

Hex editor used for:

  • Disk sector analysis
  • Binary inspection
  • File carving
  • Manipulating raw bytes

Additional Recommended DFIR Tools

Mobile Forensics

  • Cellebrite UFED
  • Magnet AXIOM Mobile

Timeline Analysis

  • log2timeline (Plaso)
  • Timesketch

Linux DFIR

  • OSQuery
  • Auditd
  • chkrootkit

Cloud Forensics

  • AWS IR tools
  • Azure Sentinel playbooks

Conclusion

This DFIR toolkit provides a wide coverage of tools for:

βœ” Disk forensics
βœ” Memory forensics
βœ” Network investigation
βœ” Malware analysis
βœ” Incident response
βœ” Registry & log analysis
βœ” USB & browser forensics
βœ” Data recovery

It is suitable for both professional IR work and DFIR learning.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors