Skadi is a free, open source collection of tools that enables the collection, processing, and advanced analysis of forensic artifacts and images. It works on MacOS, Windows, and Linux machines, scaling effectively on various platforms including laptops, desktops, servers, and the cloud. Skadi can be installed on top of hardened/gold disk images. To get started, download the latest release available in OVA, Vagrant, and Signed Installer formats. Installation instructions are provided for Docker, Vagrant, OVA, and Signed Installer. Skadi Portal provides easy access to the tools with default credentials: Username: skadi, Password: skadi.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A read-only FUSE driver that enables Linux systems to mount and access Apple File System (APFS) volumes, including encrypted and fusion drives.
A command-line tool for extracting detailed information from JPEG files, including image dimensions, compression, and metadata.
OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.
A digital investigation platform for parsing, searching, and visualizing evidences with advanced analytics capabilities.
Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.