Digital Forensics and Incident Response

Digital Forensics and Incident Response (DFIR) tools for digital forensic analysis, evidence collection, malware analysis, and cyber incident investigation.

Explore 492 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

fatt Logo

A script for extracting network metadata and fingerprints such as JA3 and HASSH from packet capture files or live network traffic.

0
BinaryPig Logo

A malware processing and analytics tool that utilizes Pig, Django, and Elasticsearch to analyze and visualize malware data.

0
Yara-Unprotect Logo

A collection of Yara rules for detecting malware evasion techniques

0
cabextract Logo

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

0
Rekall Logo

Rekall is a discontinued project that aimed to improve memory analysis methodology but faced challenges due to the nature of in-memory structure and increasing security measures.

0
Xplot Logo

A tool for analyzing TCP packet traces with color support.

0
Project Icewater Logo

A project providing open-source YARA rules for malware and malicious file detection

0
sniffle Logo

A Bluetooth 5 and 4.x sniffer using TI CC1352/CC26x2 hardware with advanced features and Python-based host-side software.

0
WindowsSCOPE Logo

A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.

0
yara-rules Logo

A repository of YARA rules for identifying and classifying malware through pattern-based detection.

0
Drltrace Logo

Drltrace is a dynamic API calls tracer for Windows and Linux applications.

0
CFR Logo

Java decompiler for modern Java features up to Java 14.

0
tcpsplit Logo

A utility for splitting packet traces along TCP connection boundaries.

0
CDQR - Cold Disk Quick Response Logo

A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.

0
WindowsSCOPE Cyber Forensics Logo

GUI-based memory forensic capture tool for cyber forensics and cyber crime investigation.

0
unfurl Logo

Unfurl is a URL analysis tool that extracts and visualizes data from URLs, breaking them down into components and presenting the information visually.

0
MFTExtractor Logo

A tool for parsing and extracting information from the Master File Table of NTFS file systems.

0
GRR Rapid Response Logo

Incident response framework focused on remote live forensics

0
Contagio Mobile Logo

A collection of Android Fakebank and Tizi samples for analyzing spyware on Android devices.

0
YARA Silly Silly Logo

A semi-automatic tool to generate YARA rules from virus samples.

0
win10upgrade Logo

MetaDefender Cloud offers advanced threat prevention using technologies like Multiscanning, Deep CDR, and Sandbox.

0
Steghide Logo

Steghide is a steganography program for hiding data in image and audio files.

0
lw-yara Logo

A Yara ruleset designed to detect PHP shells and other webserver malware for malware analysis and threat detection.

0
WinDbg Logo

Powerful debugging tool with extensive features and extensions for memory dump analysis and crash dump analysis.

0