A list of free and open forensics analysis tools and other resources
-
Updated
Jul 9, 2026
A list of free and open forensics analysis tools and other resources
Collaborative Incident Response platform
macOS forensic acquisition made simple
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR
A collection of PowerShell scripts for analyzing macOS Forensic Artifacts
Neural network RDP cache reconstruction tool
C# Library and research notes for Windows 11 Notepad State Files
Automatically create iSCSI targets for all drives except for a boot device
Unified digital forensics platform bringing disk, RAM, container drift, logical acquisition, and backup analysis together for Windows, Linux, Docker, Android, and iOS.
Valhuntir SIFT platform — MCP servers, gateway, Examiner Portal
VMDetect is a Python based Windows VM detection and environment forensics tool that reads ACPI/SMBIOS firmware tables and system artifacts to expose virtual machines, even if people try to hide them!
Is a portable forensic tool for analyzing Windows logs, pre-organized according to the methodology outlined in this job: https://cybersecuritynews.com/windows-event-log-analysis/, to quickly highlight key forensic artifacts.
Digital Forensics Essentials (DFE)
Reverse Engineering the Tabstate files for Windows Notepad
Decryption tool for LockMyPix android app
DFLER: Drone Flight Log Entity Recognizer to Support Forensic Investigation on Drone Device
Linux last-logon forensic auditing from the binary lastlog database.
Zero-dependency Python CLI for targeted file collection - digital forensics, incident response, and selective backups. Cross-platform, with SHA-256 manifests, chain-of-custody logging, and checkpoint/resume for failing media.
YAFFS2 Forensic Tool – Python-Based Partition Dumper & Recovery
To associate your repository with the forensic-tools topic, visit your repo's landing page and select "manage topics."