Skip to main content
ToolLicensePlatformsPricingAction
AutopsyApache-2.0Windows, Linux, macOSOpen SourceProfile
ChainsawGPL-3.0-onlyLinux, Windows, macOSOpen SourceProfile
Cyber TriageProprietaryWindowsCommercialProfile
DFIR-IRISLGPL-3.0-or-laterLinux, WebOpen SourceProfile
KAPEKroll End User License Agreement (proprietary)WindowsFree / CommercialProfile
MemProcFSAGPL-3.0-or-laterLinux, WindowsOpen SourceProfile
PlasoApache-2.0Linux, macOS, WindowsOpen SourceProfile
RedlineProprietary freewareWindowsFreeProfile
The Sleuth KitCommon Public License 1.0 / IBM Public License / GPL-2.0 / MIT / BSD-3-Clause (mixed)Windows, Linux, macOSOpen SourceProfile
TheHiveProprietaryLinux, WebFreemiumProfile
VelociraptorAGPL-3.0-or-laterLinux, macOS, Windows, FreeBSDOpen SourceProfile
VolatilityVolatility Software License (VSL) v1.0Windows, Linux, macOSFreeProfile

Software in Digital Forensics

Autopsy

Open Source

Open-source graphical digital forensics platform built on The Sleuth Kit for disk image, file system, and web artifact analysis with timelines.

LicenseApache-2.0
PlatformWindows, Linux, macOS

Chainsaw

Open Source

Applies Sigma and custom rules to search Windows event logs, MFT records, registry hives, and SRUM data for rapid incident triage.

LicenseGPL-3.0-only
PlatformLinux, Windows, macOS

Cyber Triage

Commercial

Automated endpoint forensics tool that collects artifacts and scores them for investigation.

LicenseProprietary
PlatformWindows

DFIR-IRIS

Open Source

Open source collaborative incident response platform for cases, timelines, evidence, and alerts.

LicenseLGPL-3.0-or-later
PlatformLinux, Web

KAPE

Free / Commercial

Kroll Artifact Parser and Extractor for rapid Windows triage that collects and parses registry, event log, and browser artifacts from live systems.

LicenseKroll End User License Agreement (proprietary)
PlatformWindows

MemProcFS

Open Source

Memory forensics framework that mounts physical memory dumps and live memory as a virtual file system.

LicenseAGPL-3.0-or-later
PlatformLinux, Windows

Plaso

Open Source

DFIR timeline generation engine that parses logs, disk images, and artifacts to create unified event timelines for incident investigations.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Free endpoint investigation tool from FireEye that collects and analyzes memory, processes, and files to triage suspicious activity.

LicenseProprietary freeware
PlatformWindows

The Sleuth Kit

Open Source

C library and command-line tools for disk and file system forensics that parse NTFS, FAT, EXT, HFS+, and APFS images to recover deleted files.

LicenseCommon Public License 1.0 / IBM Public License / GPL-2.0 / MIT / BSD-3-Clause (mixed)
PlatformWindows, Linux, macOS

TheHive

Freemium

SOC case management platform, now freemium under StrangeBee after its open source era.

LicenseProprietary
PlatformLinux, Web

Velociraptor

Open Source

Endpoint visibility and digital forensics tool using VQL queries to collect system artifacts and hunt threats across hosts.

LicenseAGPL-3.0-or-later
PlatformLinux, macOS, Windows, FreeBSD

Free memory forensics framework that extracts processes, network connections, and injected code from RAM snapshots without OS profiles.

LicenseVolatility Software License (VSL) v1.0
PlatformWindows, Linux, macOS

Frequently Asked Questions

What is Digital Forensics?

Digital forensics and incident response tools capture and analyze disk images, memory, and endpoint artifacts to investigate breaches, reconstruct attacker activity, and triage malware. Network packet capture and protocol analysis tools are in the network-monitoring category.

What topics does the Digital Forensics category cover?

Disk Forensics, Memory Analysis & Acquisition, Malware Sandboxing & Triage, Endpoint Artifact Collection, Timeline Reconstruction

About Digital Forensics

Digital forensics and incident response (DFIR) tools capture and analyze digital evidence after a security incident. The category includes disk forensics tools that create and examine forensic disk images, memory forensics frameworks that extract processes, network connections, and injected code from RAM dumps, and malware sandboxes that execute suspicious files in isolated environments to observe their behavior. Incident response platforms collect artifacts from endpoints across an organization, letting analysts search for indicators of compromise at scale. Tools like Autopsy and The Sleuth Kit provide graphical and command-line interfaces for disk image analysis, while Volatility processes memory dumps to reconstruct running processes and detect rootkits. Sandboxes like CAPE execute malware samples and produce reports on file system changes, network communications, and registry modifications. Endpoint collection tools like KAPE and Velociraptor gather forensic artifacts rapidly across thousands of machines, which is necessary when incident scope is unknown. The category overlaps with detection engineering, since IOCs discovered during DFIR investigations feed back into detection rules for future prevention.

Covered Topics & Disciplines

Disk ForensicsMemory Analysis & AcquisitionMalware Sandboxing & TriageEndpoint Artifact CollectionTimeline Reconstruction