Loading...
Digital Forensics tools for Linux: the Digital Forensics options most relevant when Linux is the priority, compared side by side so you can shortlist faster. Filter by pricing or specialization. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
We cover 21 cybersecurity tools
Cloud-native system call and audit log analysis tool based on Wireshark
A read-only FUSE driver that enables Linux systems to mount and access Apple File System (APFS) volumes, including encrypted and fusion drives.
A comprehensive Linux log analysis tool that streamlines the investigation of security incidents by extracting and organizing critical details from supported log files.
A utility for recovering deleted files from ext3 or ext4 partitions.
Margarita Shotgun is a Python tool that enables remote memory acquisition from target systems through command line interface, supporting Linux distributions and other operating systems via Docker containers.
pcapfex is a forensic tool that extracts files from packet capture data by analyzing network traffic and identifying embedded file content.
SIFT is a digital forensics toolkit that provides installation management, task execution, and machine image building capabilities for forensic investigations on Ubuntu systems.
A command-line forensics tool for tracking and analyzing USB device artifacts and connection history on Linux systems.
A bash script for automating Linux swap analysis for post-exploitation or forensics purposes.
CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.
Porting GNU/Linux userland tools to the bionic/Linux userland of Android to provide access to the audit stream for Android applications with minimal overhead.
A portable Rust-based tool for acquiring volatile memory from Linux systems without requiring prior knowledge of the target OS distribution or kernel.
Python tool for remotely or locally dumping RAM of a Linux client for digital forensics analysis.
AMExtractor is an Android memory acquisition tool that dumps physical device memory using /dev/kmem without requiring kernel source code.
POFR is a Linux forensic data collection system that captures process execution, file access, and network activity for incident response and compliance analysis.
A Cross-Platform Forensic Framework for Google Chrome that allows investigation of history, downloads, bookmarks, cookies, and provides a full report.
A deprecated digital forensics tool by Netflix that helped investigators scope compromises across AWS cloud instances by identifying behavioral differences and outliers during security incidents.
A tool for creating compact Linux memory dumps compatible with popular debugging tools.
wxHexEditor is a free cross-platform hex editor and disk editor for editing binary files, disk devices, and logical drives with data manipulation and checksum calculation features.
LiME is a Linux Memory Extractor tool for acquiring volatile memory from Linux and Linux-based devices, including Android, with features like full memory captures and minimal process footprint.
A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.