Skip to content
Tools & Resources

The Forensic Toolkit

Every tool referenced across this site, in one filterable catalog.

Showing 39 of 39 tools

Commercial

Cellebrite UFED

Mobile Forensics · Windows

Industry-standard mobile extraction suite supporting logical, file-system, and physical acquisition across thousands of device profiles.

Official site
Commercial

Magnet AXIOM

Mobile Forensics · Windows

Unified mobile, computer, and cloud forensic platform with artifact-centric analysis and strong timeline/carving capability.

Official site
Commercial

MSAB XRY

Mobile Forensics · Windows

Mobile extraction and decoding toolkit widely used by law enforcement, with strong app-data parsing.

Official site
Commercial

Oxygen Forensic Detective

Mobile Forensics · Windows

Mobile and cloud extraction platform with deep app support and built-in link-analysis tooling.

Official site
Open-Source

ALEAPP

Mobile Forensics · Cross-platform

Android Logs Events And Protobuf Parser — automates parsing of Android artifacts from an extraction.

Official site
Open-Source

iLEAPP

Mobile Forensics · Cross-platform

iOS Logs Events And Plists Parser — automates parsing of iOS backup and full file-system extractions.

Official site
Open-Source

Andriller

Mobile Forensics · Windows / Linux

Android forensic acquisition and decoding utility with screen-lock bypass helpers for supported devices.

Official site
Open-Source

libimobiledevice

Mobile Forensics · Cross-platform

Cross-platform library for communicating with iOS devices without iTunes — the backbone of many iOS acquisition tools.

Official site
Free

ADB (Android Debug Bridge)

Mobile Forensics · Cross-platform

Official Android command-line tool used for logical backups, file pulls, and shell-level device interaction.

Official site
Open-Source

Autopsy

Disk Forensics · Windows / Linux / macOS

Graphical front-end to The Sleuth Kit offering timeline analysis, keyword search, and artifact modules.

Official site
Open-Source

The Sleuth Kit

Disk Forensics · Windows / Linux / macOS

Command-line library of file-system and volume analysis tools underpinning Autopsy and many custom workflows.

Official site
Free

FTK Imager

Disk Forensics · Windows

Free imaging utility for creating forensic images (RAW/E01), previewing evidence, and exporting files without altering originals.

Official site
Open-Source

Guymager

Disk Forensics · Linux

Fast, GUI-based Linux disk imaging tool supporting RAW and EWF/E01 output with built-in hashing.

Official site
Open-Source

dcfldd

Disk Forensics · Linux

Forensic variant of dd with on-the-fly hashing, verification, and progress reporting for imaging.

Official site
Open-Source

PhotoRec

Disk Forensics · Windows / Linux / macOS

File-carving utility that recovers files from unallocated space based on signature matching, ignoring file-system structures.

Official site
Open-Source

Scalpel

Disk Forensics · Linux

Fast, configurable file carver that scans raw images against user-defined header/footer signatures.

Official site
Open-Source

Foremost

Disk Forensics · Linux

Originally built for the US Air Force OSI — recovers files based on headers, footers, and internal data structures.

Official site
Open-Source

log2timeline / Plaso

Disk Forensics · Windows / Linux / macOS

Super-timeline generation framework that parses hundreds of artifact types into a single sortable timeline.

Official site
Free

Registry Explorer

Disk Forensics · Windows

Eric Zimmerman's registry hive viewer with deleted-key recovery and bookmarked keys for fast triage.

Official site
Commercial

Maltego

OSINT · Windows / Linux / macOS

Link-analysis platform that runs 'transforms' against entities (domains, emails, people) to visually map relationships.

Official site
Open-Source

Sherlock

OSINT · Cross-platform

Command-line tool that hunts for a given username across 400+ social platforms.

Official site
Open-Source

theHarvester

OSINT · Cross-platform

Gathers emails, subdomains, hosts, and employee names from public sources and search engines.

Official site
Commercial

Shodan

OSINT · Web

Search engine for internet-connected devices and exposed services — critical for infrastructure recon.

Official site
Commercial

Censys

OSINT · Web

Internet-wide scanning platform for certificate, host, and service discovery.

Official site
Free

Have I Been Pwned

OSINT · Web

Breach-data lookup service used to validate whether an email or domain appeared in known breaches.

Official site
Free

Wayback Machine

OSINT · Web

Internet Archive's historical web snapshot tool — essential for recovering deleted or edited web content.

Official site
Open-Source

SpiderFoot

OSINT · Cross-platform

Automated OSINT reconnaissance tool that aggregates data from 200+ sources against a target.

Official site
Open-Source

Wireshark

Network Forensics · Windows / Linux / macOS

The de facto standard packet-capture and protocol-analysis tool for network traffic investigation.

Official site
Open-Source

tcpdump

Network Forensics · Linux / macOS

Lightweight command-line packet capture utility ideal for headless servers and scripted capture.

Official site
Free

NetworkMiner

Network Forensics · Windows / Linux

Passive network forensic analysis tool that reconstructs files, sessions, and host profiles from captures.

Official site
Free

Python (pandas)

CDR/IPDR Analysis · Cross-platform

The standard toolkit for cleaning, joining, and analyzing large CDR/IPDR dumps beyond what spreadsheets can comfortably handle.

Official site
Open-Source

QGIS

CDR/IPDR Analysis · Windows / Linux / macOS

Open-source GIS platform used to plot cell tower sector cones, azimuth overlap, and movement timelines on a map.

Official site
Commercial

Microsoft Excel / Power Query

CDR/IPDR Analysis · Windows / macOS

Widely used for cleaning, pivoting, and cross-referencing moderate-sized CDR/IPDR exports in casework.

Official site
Open-Source

Volatility 3

Memory Forensics · Cross-platform

The leading open-source memory-forensics framework for analyzing RAM captures across Windows, Linux, and macOS.

Official site
Free

DumpIt

Memory Forensics · Windows

Single-click RAM acquisition tool that produces a raw memory image for offline analysis.

Official site
Open-Source

LiME

Memory Forensics · Linux

Loadable Kernel Module for acquiring volatile memory from Linux (and Linux-based Android) devices.

Official site
Open-Source

AVML

Memory Forensics · Linux

Microsoft's Acquire Volatile Memory for Linux — a portable, static binary for capturing RAM from cloud VMs.

Official site
Free

HashCalc / sha256sum

Integrity & Hashing · Cross-platform

Command-line and GUI hashing utilities used to verify image and evidence integrity via MD5/SHA-1/SHA-256.

Official site
Commercial

EnCase Forensic

Suite · Windows

Long-standing commercial forensic suite covering acquisition, analysis, and courtroom reporting.

Official site