Skip to main content

Digital Forensics & Incident Response (DFIR)

Digital forensics and incident response tools capture and analyze disk images, memory, and endpoint artifacts to investigate breaches, reconstruct attacker activity, and triage malware. Network packet capture and protocol analysis tools are in the network-monitoring category.

9 Tools Cataloged
ToolLicensePlatformsPricingAction
AutopsyApache-2.0Windows, Linux, macOSOpen SourceProfile
CAPE SandboxGPL-3.0-or-laterLinuxOpen SourceProfile
ChainsawGPL-3.0-onlyLinux, Windows, macOSOpen SourceProfile
KAPEKroll End User License Agreement (proprietary)WindowsFree / CommercialProfile
PlasoApache-2.0Linux, macOS, WindowsOpen SourceProfile
RedlineProprietary freewareWindowsFreeProfile
The Sleuth KitCommon Public License 1.0 / IBM Public License / GPL-2.0 / MIT / BSD-3-Clause (mixed)Windows, Linux, macOSOpen SourceProfile
VelociraptorAGPL-3.0-or-laterLinux, macOS, Windows, FreeBSDOpen SourceProfile
VolatilityVolatility Software License (VSL) v1.0Windows, Linux, macOSFreeProfile

Tools in Digital Forensics & Incident Response (DFIR)

Autopsy

Open Source

Open-source graphical digital forensics platform built on The Sleuth Kit for disk image, file system, and web artifact analysis with timelines.

LicenseApache-2.0
PlatformWindows, Linux, macOS

CAPE Sandbox

Open Source

Open-source malware analysis sandbox derived from Cuckoo that adds automated unpacking, debugger integration, and C2 configuration extraction.

LicenseGPL-3.0-or-later
PlatformLinux

Chainsaw

Open Source

Applies Sigma and custom rules to search Windows event logs, MFT records, registry hives, and SRUM data for rapid incident triage.

LicenseGPL-3.0-only
PlatformLinux, Windows, macOS

KAPE

Free / Commercial

Kroll Artifact Parser and Extractor for rapid Windows triage that collects and parses registry, event log, and browser artifacts from live systems.

LicenseKroll End User License Agreement (proprietary)
PlatformWindows

Plaso

Open Source

DFIR timeline generation engine that parses logs, disk images, and artifacts to create unified event timelines for incident investigations.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Free endpoint investigation tool from FireEye that collects and analyzes memory, processes, and files to triage suspicious activity.

LicenseProprietary freeware
PlatformWindows

The Sleuth Kit

Open Source

C library and command-line tools for disk and file system forensics that parse NTFS, FAT, EXT, HFS+, and APFS images to recover deleted files.

LicenseCommon Public License 1.0 / IBM Public License / GPL-2.0 / MIT / BSD-3-Clause (mixed)
PlatformWindows, Linux, macOS

Velociraptor

Open Source

Endpoint visibility and digital forensics tool using VQL queries to collect system artifacts and hunt threats across hosts.

LicenseAGPL-3.0-or-later
PlatformLinux, macOS, Windows, FreeBSD

Free memory forensics framework that extracts processes, network connections, and injected code from RAM snapshots without OS profiles.

LicenseVolatility Software License (VSL) v1.0
PlatformWindows, Linux, macOS

Frequently Asked Questions

What is Digital Forensics & Incident Response (DFIR)?

Digital forensics and incident response tools capture and analyze disk images, memory, and endpoint artifacts to investigate breaches, reconstruct attacker activity, and triage malware. Network packet capture and protocol analysis tools are in the network-monitoring category.

What topics does the Digital Forensics & Incident Response (DFIR) category cover?

Disk Forensics, Memory Analysis & Acquisition, Malware Sandboxing & Triage, Endpoint Artifact Collection, Timeline Reconstruction

About Digital Forensics & Incident Response (DFIR)

Digital forensics and incident response (DFIR) tools capture and analyze digital evidence after a security incident. The category includes disk forensics tools that create and examine forensic disk images, memory forensics frameworks that extract processes, network connections, and injected code from RAM dumps, and malware sandboxes that execute suspicious files in isolated environments to observe their behavior. Incident response platforms collect artifacts from endpoints across an organization, letting analysts search for indicators of compromise at scale. Tools like Autopsy and The Sleuth Kit provide graphical and command-line interfaces for disk image analysis, while Volatility processes memory dumps to reconstruct running processes and detect rootkits. Sandboxes like CAPE execute malware samples and produce reports on file system changes, network communications, and registry modifications. Endpoint collection tools like KAPE and Velociraptor gather forensic artifacts rapidly across thousands of machines, which is necessary when incident scope is unknown. The category overlaps with detection engineering, since IOCs discovered during DFIR investigations feed back into detection rules for future prevention.

Covered Topics & Disciplines

Disk ForensicsMemory Analysis & AcquisitionMalware Sandboxing & TriageEndpoint Artifact CollectionTimeline Reconstruction