Loading...
Digital Forensics tools for Windows: the Digital Forensics options most relevant when Windows is the priority, compared side by side so you can shortlist faster. Filter by pricing or specialization. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
We cover 31 cybersecurity tools
Password recovery tool for encrypted ZIP, 7Zip, and RAR archives.
Decrypts EFS-protected files on NTFS volumes across Windows versions.
Password recovery tool for MS Office, WordPerfect, Lotus & other office docs.
Instantly recovers passwords from IBM/Lotus SmartSuite documents.
Recovers/removes passwords and restrictions from encrypted PDF files.
Extracts resources (bitmaps, icons, cursors, AVI movies, HTML files, and more) from dll files
A pure Python parser for Windows Event Log (.evtx) files that enables cross-platform forensic analysis of Windows system events.
A PowerShell-based DFIR automation tool that streamlines artifact and evidence collection from Windows machines for digital forensic investigations.
CyLR is a Live Response Collection tool for quickly and securely collecting forensic artifacts from hosts with NTFS file systems.
WinSearchDBAnalyzer can parse and recover records in Windows.edb, providing detailed insights into various data types.
A digital forensics tool that extracts and analyzes Windows AppCompat and AmCache registry data for enterprise-scale forensic investigations.
Dependencies is an open-source modern replacement for Dependency Walker that helps Windows developers analyze and troubleshoot DLL load dependency issues.
GrokEVT is a tool for reading Windows event log files and converting them to a human-readable format.
RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.
A Cross-Platform Forensic Framework for Google Chrome that allows investigation of history, downloads, bookmarks, cookies, and provides a full report.
wxHexEditor is a free cross-platform hex editor and disk editor for editing binary files, disk devices, and logical drives with data manipulation and checksum calculation features.
DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.
Generate comprehensive reports about Windows systems with detailed system, security, networking, and USB information.
Automated collection tool for incident response triage in Windows systems.
A Windows Registry hive extraction library that provides C API access for reading and writing registry binary files with XML export capabilities.
A tool that collects and displays user activity and system events on a Windows system.