Digital Forensics and Incident Response

Digital Forensics and Incident Response (DFIR) tools for digital forensic analysis, evidence collection, malware analysis, and cyber incident investigation.

Explore 492 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Intelligence-Driven Incident Response Logo

ENISA Training Resources offers online training material for cybersecurity specialists, covering technical areas such as artefact handling and analysis.

1
CrowdFMS Logo

CrowdFMS is a CrowdStrike framework that automates malware sample collection from VirusTotal using YARA rule-based notifications and the Private API system.

0
DFTimewolf Logo

A framework for orchestrating forensic collection, processing, and data export.

0
ssm-acquire Logo

A Python module for orchestrating remote forensic data acquisition and analysis from Linux instances using Amazon SSM.

0
ConventionEngine Logo

ConventionEngine is a Yara rule collection that analyzes PE files by examining PDB paths for suspicious keywords, terms, and anomalies that may indicate malicious software.

0
Yara-Java Logo

Embeddable Yara library for Java with support for loading rules and scanning data.

0
dcfldd Logo

A modified version of GNU dd with added features like hashing and fast disk wiping.

0
Triton Logo

Dynamic binary analysis library with various analysis and emulation capabilities.

0
AWS Incident Response Investigation of API activity using Athena and notification of actions using EventBridge Logo

An AWS incident response framework that uses Athena to analyze CloudTrail events and EventBridge for notifications to investigate API activity and detect security misconfigurations.

0
ALEAPP Android Logs Events And Protobuf Parser Logo

ALEAPP is a Python-based forensic tool for parsing Android logs, events, and protobuf data with both CLI and GUI interfaces.

0
stego Logo

Steganographic Swiss army knife for encoding and decoding data into images.

0
Pwndbg Logo

Pwndbg is a GDB plug-in that enhances the debugging experience for low-level software developers, hardware hackers, reverse-engineers, and exploit developers.

0
YaraHunter Logo

YaraHunter scans container images, running Docker containers, and filesystems using YARA rules to detect malware indicators and signs of compromise.

0
Orochi Logo

Orochi is a collaborative forensic memory dump analysis framework.

0
RegRippy Logo

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

0
mac_apt Logo

mac_apt is a versatile DFIR tool for processing Mac and iOS images, offering extensive artifact extraction capabilities and cross-platform support.

0
Yara_fn IDAPython script Logo

An IDAPython script that generates YARA rules for basic blocks of the current function in IDA Pro, with automatic masking of relocation bytes and optional validation against file segments.

0
PcapXray Logo

A network forensics tool for visualizing packet captures as network diagrams with detailed analysis.

0
bro-osquery-module Logo

A module for loading Bro logs as tables in Osquery

0
Belkasoft Logo

Belkasoft offers cybersecurity solutions, training, and tools for businesses, law enforcement, and academia.

0
LastActivityView Logo

A tool that collects and displays user activity and system events on a Windows system.

0
HxD Logo

HxD is a freeware hex editor and disk editor with advanced features for editing files, memory, and disks.

0
Binsequencer Logo

Binsequencer automatically generates YARA detection rules by analyzing collections of similar malware samples and identifying common x86 instruction sequences across the corpus.

0

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →