Forensic Downloads
Select the operating system you are examining, then choose tools to collect evidence, parse forensic artifacts or analyze the resulting data.
Download tools from the original developer or official release repository whenever possible. Verify hashes or digital signatures where provided and document tool versions used during evidentiary acquisition and examination.
Windows
Collection, artifact parsing and analysis utilities for Windows endpoints and forensic images.
01 Collect / Acquire
KAPE
Kroll Artifact Parser and Extractor rapidly collects targeted Windows forensic artifacts such as Registry hives, event logs, browser data, filesystem metadata and other evidence relevant to incident response.
KAPEWinPmem
Physical-memory acquisition utility for capturing Windows RAM for later analysis with tools such as Volatility.
WinPmem ReleasesFTK Imager
Widely used forensic imaging utility for acquiring physical disks, logical volumes and individual files while supporting evidence preview and hashing.
FTK DownloadsVelociraptor
Endpoint collection and investigation framework capable of targeted artifact acquisition from individual Windows hosts or large fleets.
Velociraptor02 Parse / Extract Artifacts
Eric Zimmerman’s Tools
One of the most useful collections of Windows forensic parsers. Includes utilities for Registry hives, MFT records, ShellBags, LNK files, Jump Lists, Amcache and numerous other artifacts.
Zimmerman ToolsRegRipper
Plugin-driven forensic framework for extracting relevant information from Windows Registry hives.
RegRipperChainsaw
Fast artifact hunting and parsing tool with support for Windows Event Logs, Sigma detections, MFT analysis and several other Windows evidence sources.
Chainsaw Releases03 Analyze / Hunt
Hayabusa
Windows Event Log forensic timeline generator and threat-hunting tool using Sigma-compatible detection rules for rapid incident analysis.
Hayabusa ReleasesVolatility 3
Memory-forensics framework for analyzing processes, DLLs, network connections, injected code, kernel structures and other runtime evidence contained in RAM.
Volatility 3Microsoft Sysinternals
Collection including Process Explorer, Process Monitor, Autoruns, TCPView, Sigcheck, Strings and other utilities useful during live-response and endpoint investigations.
Sysinternals SuitemacOS
Tools focused on APFS/HFS systems, Apple artifacts, unified logs, browser history, persistence and endpoint collection.
01 Collect / Acquire
UAC — Unix-like Artifacts Collector
Portable incident-response collector capable of gathering process information, user and system data, logs, configuration files, filesystem metadata and other forensic artifacts from macOS systems.
UACVelociraptor
Provides targeted macOS artifact collection and endpoint investigation. Current official releases include native Apple Silicon builds.
VelociraptorArtifactCollector
Portable collector designed to gather predefined forensic artifacts from macOS as well as Windows and Linux endpoints.
ArtifactCollector02 Parse / Extract Artifacts
mac_apt
Purpose-built macOS forensic parsing framework supporting disk images and artifact collections. Parses Safari history, Spotlight, FSEvents, Unified Logs, persistence information, recent files, network artifacts and many other Apple evidence sources.
mac_aptAPOLLO
Apple Pattern of Life Lazy Output’er extracts pattern-of-life information from Apple databases and can produce structured CSV and SQLite output for forensic examination.
APOLLO03 Analyze / Hunt
Plaso / log2timeline
Creates consolidated forensic timelines by extracting timestamped events from many different filesystem and artifact sources.
Plaso ReleasesVolatility 3
Can examine supported macOS memory captures for runtime evidence, process information and other volatile artifacts.
Volatility 3Objective-See TaskExplorer
Interactive macOS process inspection tool showing signatures, loaded dynamic libraries, open files and network connections. Useful during live-response investigations.
TaskExplorerLinux / Unix
Incident-response collection and forensic analysis utilities for Linux servers, workstations and Unix-like systems.
01 Collect / Acquire
UAC
One of the strongest open-source choices for Unix-like incident response. Collects processes, executable hashes, logs, configuration files, user information, filesystem metadata and other evidence while respecting order-of-volatility principles.
UACVelociraptor
Endpoint investigation platform suitable for remote Linux artifact collection and threat hunting across multiple hosts.
VelociraptorArtifactCollector
Portable collection agent with prebuilt Linux versions for gathering common forensic artifacts during triage.
ArtifactCollector02 Parse / Extract Artifacts
Plaso / log2timeline
Parses large numbers of filesystem and application artifacts and combines timestamped activity into a structured forensic timeline.
Plaso ReleasesThe Sleuth Kit
Command-line forensic utilities for examining filesystems, deleted entries, inode metadata and disk-image structures.
Sleuth Kit03 Analyze / Hunt
Volatility 3
Supports analysis of Linux memory captures when appropriate kernel symbol information is available.
Volatility 3Timesketch
Collaborative timeline-analysis platform for searching, filtering and investigating large forensic timelines produced from endpoint evidence.
TimesketchCross-Platform DFIR
Tools intentionally useful across multiple operating systems or evidence types.
Velociraptor
Remote forensic collection, endpoint visibility and threat hunting across supported Windows, Linux and macOS environments.
VelociraptorVolatility 3
Cross-platform forensic framework for extracting evidence from volatile-memory captures originating from Windows, Linux and supported macOS systems.
Volatility 3Plaso
Forensic event parsing framework used to create consolidated timelines from many artifact and filesystem sources.
PlasoArtifactCollector
Portable forensic collection utility with prebuilt releases for Windows, Linux and macOS.
ArtifactCollector