The Forensic Toolkit
Every tool referenced across this site, in one filterable catalog.
Showing 39 of 39 tools
Cellebrite UFED
Mobile Forensics · Windows
Industry-standard mobile extraction suite supporting logical, file-system, and physical acquisition across thousands of device profiles.
Official siteMagnet AXIOM
Mobile Forensics · Windows
Unified mobile, computer, and cloud forensic platform with artifact-centric analysis and strong timeline/carving capability.
Official siteMSAB XRY
Mobile Forensics · Windows
Mobile extraction and decoding toolkit widely used by law enforcement, with strong app-data parsing.
Official siteOxygen Forensic Detective
Mobile Forensics · Windows
Mobile and cloud extraction platform with deep app support and built-in link-analysis tooling.
Official siteALEAPP
Mobile Forensics · Cross-platform
Android Logs Events And Protobuf Parser — automates parsing of Android artifacts from an extraction.
Official siteiLEAPP
Mobile Forensics · Cross-platform
iOS Logs Events And Plists Parser — automates parsing of iOS backup and full file-system extractions.
Official siteAndriller
Mobile Forensics · Windows / Linux
Android forensic acquisition and decoding utility with screen-lock bypass helpers for supported devices.
Official sitelibimobiledevice
Mobile Forensics · Cross-platform
Cross-platform library for communicating with iOS devices without iTunes — the backbone of many iOS acquisition tools.
Official siteADB (Android Debug Bridge)
Mobile Forensics · Cross-platform
Official Android command-line tool used for logical backups, file pulls, and shell-level device interaction.
Official siteAutopsy
Disk Forensics · Windows / Linux / macOS
Graphical front-end to The Sleuth Kit offering timeline analysis, keyword search, and artifact modules.
Official siteThe Sleuth Kit
Disk Forensics · Windows / Linux / macOS
Command-line library of file-system and volume analysis tools underpinning Autopsy and many custom workflows.
Official siteFTK Imager
Disk Forensics · Windows
Free imaging utility for creating forensic images (RAW/E01), previewing evidence, and exporting files without altering originals.
Official siteGuymager
Disk Forensics · Linux
Fast, GUI-based Linux disk imaging tool supporting RAW and EWF/E01 output with built-in hashing.
Official sitedcfldd
Disk Forensics · Linux
Forensic variant of dd with on-the-fly hashing, verification, and progress reporting for imaging.
Official sitePhotoRec
Disk Forensics · Windows / Linux / macOS
File-carving utility that recovers files from unallocated space based on signature matching, ignoring file-system structures.
Official siteScalpel
Disk Forensics · Linux
Fast, configurable file carver that scans raw images against user-defined header/footer signatures.
Official siteForemost
Disk Forensics · Linux
Originally built for the US Air Force OSI — recovers files based on headers, footers, and internal data structures.
Official sitelog2timeline / Plaso
Disk Forensics · Windows / Linux / macOS
Super-timeline generation framework that parses hundreds of artifact types into a single sortable timeline.
Official siteRegistry Explorer
Disk Forensics · Windows
Eric Zimmerman's registry hive viewer with deleted-key recovery and bookmarked keys for fast triage.
Official siteMaltego
OSINT · Windows / Linux / macOS
Link-analysis platform that runs 'transforms' against entities (domains, emails, people) to visually map relationships.
Official siteSherlock
OSINT · Cross-platform
Command-line tool that hunts for a given username across 400+ social platforms.
Official sitetheHarvester
OSINT · Cross-platform
Gathers emails, subdomains, hosts, and employee names from public sources and search engines.
Official siteShodan
OSINT · Web
Search engine for internet-connected devices and exposed services — critical for infrastructure recon.
Official siteCensys
OSINT · Web
Internet-wide scanning platform for certificate, host, and service discovery.
Official siteHave I Been Pwned
OSINT · Web
Breach-data lookup service used to validate whether an email or domain appeared in known breaches.
Official siteWayback Machine
OSINT · Web
Internet Archive's historical web snapshot tool — essential for recovering deleted or edited web content.
Official siteSpiderFoot
OSINT · Cross-platform
Automated OSINT reconnaissance tool that aggregates data from 200+ sources against a target.
Official siteWireshark
Network Forensics · Windows / Linux / macOS
The de facto standard packet-capture and protocol-analysis tool for network traffic investigation.
Official sitetcpdump
Network Forensics · Linux / macOS
Lightweight command-line packet capture utility ideal for headless servers and scripted capture.
Official siteNetworkMiner
Network Forensics · Windows / Linux
Passive network forensic analysis tool that reconstructs files, sessions, and host profiles from captures.
Official sitePython (pandas)
CDR/IPDR Analysis · Cross-platform
The standard toolkit for cleaning, joining, and analyzing large CDR/IPDR dumps beyond what spreadsheets can comfortably handle.
Official siteQGIS
CDR/IPDR Analysis · Windows / Linux / macOS
Open-source GIS platform used to plot cell tower sector cones, azimuth overlap, and movement timelines on a map.
Official siteMicrosoft Excel / Power Query
CDR/IPDR Analysis · Windows / macOS
Widely used for cleaning, pivoting, and cross-referencing moderate-sized CDR/IPDR exports in casework.
Official siteVolatility 3
Memory Forensics · Cross-platform
The leading open-source memory-forensics framework for analyzing RAM captures across Windows, Linux, and macOS.
Official siteDumpIt
Memory Forensics · Windows
Single-click RAM acquisition tool that produces a raw memory image for offline analysis.
Official siteLiME
Memory Forensics · Linux
Loadable Kernel Module for acquiring volatile memory from Linux (and Linux-based Android) devices.
Official siteAVML
Memory Forensics · Linux
Microsoft's Acquire Volatile Memory for Linux — a portable, static binary for capturing RAM from cloud VMs.
Official siteHashCalc / sha256sum
Integrity & Hashing · Cross-platform
Command-line and GUI hashing utilities used to verify image and evidence integrity via MD5/SHA-1/SHA-256.
Official siteEnCase Forensic
Suite · Windows
Long-standing commercial forensic suite covering acquisition, analysis, and courtroom reporting.
Official site