September 1, 2026

Downloads

404ensics // Investigator Toolkit

Forensic Downloads

Select the operating system you are examining, then choose tools to collect evidence, parse forensic artifacts or analyze the resulting data.

⚠ FORENSIC TOOL VERIFICATION

Download tools from the original developer or official release repository whenever possible. Verify hashes or digital signatures where provided and document tool versions used during evidentiary acquisition and examination.

Windows

Collection, artifact parsing and analysis utilities for Windows endpoints and forensic images.

01 Collect / Acquire

FREE TRIAGE ARTIFACT COLLECTION

KAPE

Kroll Artifact Parser and Extractor rapidly collects targeted Windows forensic artifacts such as Registry hives, event logs, browser data, filesystem metadata and other evidence relevant to incident response.

KAPE
OPEN SOURCE RAM ACQUISITION

WinPmem

Physical-memory acquisition utility for capturing Windows RAM for later analysis with tools such as Volatility.

WinPmem Releases
DISK IMAGE EVIDENCE

FTK Imager

Widely used forensic imaging utility for acquiring physical disks, logical volumes and individual files while supporting evidence preview and hashing.

FTK Downloads
OPEN SOURCE REMOTE COLLECTION IR

Velociraptor

Endpoint collection and investigation framework capable of targeted artifact acquisition from individual Windows hosts or large fleets.

Velociraptor

02 Parse / Extract Artifacts

FREE REGISTRY MFT LNK

Eric Zimmerman’s Tools

One of the most useful collections of Windows forensic parsers. Includes utilities for Registry hives, MFT records, ShellBags, LNK files, Jump Lists, Amcache and numerous other artifacts.

Zimmerman Tools
OPEN SOURCE REGISTRY

RegRipper

Plugin-driven forensic framework for extracting relevant information from Windows Registry hives.

RegRipper
OPEN SOURCE EVTX MFT

Chainsaw

Fast artifact hunting and parsing tool with support for Windows Event Logs, Sigma detections, MFT analysis and several other Windows evidence sources.

Chainsaw Releases

03 Analyze / Hunt

OPEN SOURCE EVTX SIGMA TIMELINE

Hayabusa

Windows Event Log forensic timeline generator and threat-hunting tool using Sigma-compatible detection rules for rapid incident analysis.

Hayabusa Releases
OPEN SOURCE MEMORY

Volatility 3

Memory-forensics framework for analyzing processes, DLLs, network connections, injected code, kernel structures and other runtime evidence contained in RAM.

Volatility 3
FREE LIVE RESPONSE

Microsoft Sysinternals

Collection including Process Explorer, Process Monitor, Autoruns, TCPView, Sigcheck, Strings and other utilities useful during live-response and endpoint investigations.

Sysinternals Suite

macOS

Tools focused on APFS/HFS systems, Apple artifacts, unified logs, browser history, persistence and endpoint collection.

01 Collect / Acquire

OPEN SOURCE TRIAGE MACOS

UAC — Unix-like Artifacts Collector

Portable incident-response collector capable of gathering process information, user and system data, logs, configuration files, filesystem metadata and other forensic artifacts from macOS systems.

UAC
OPEN SOURCE REMOTE COLLECTION ARM64

Velociraptor

Provides targeted macOS artifact collection and endpoint investigation. Current official releases include native Apple Silicon builds.

Velociraptor
OPEN SOURCE ARTIFACT COLLECTION

ArtifactCollector

Portable collector designed to gather predefined forensic artifacts from macOS as well as Windows and Linux endpoints.

ArtifactCollector

02 Parse / Extract Artifacts

OPEN SOURCE APFS UNIFIED LOGS SAFARI

mac_apt

Purpose-built macOS forensic parsing framework supporting disk images and artifact collections. Parses Safari history, Spotlight, FSEvents, Unified Logs, persistence information, recent files, network artifacts and many other Apple evidence sources.

mac_apt
OPEN SOURCE APPLE PATTERN OF LIFE

APOLLO

Apple Pattern of Life Lazy Output’er extracts pattern-of-life information from Apple databases and can produce structured CSV and SQLite output for forensic examination.

APOLLO

03 Analyze / Hunt

OPEN SOURCE TIMELINE

Plaso / log2timeline

Creates consolidated forensic timelines by extracting timestamped events from many different filesystem and artifact sources.

Plaso Releases
OPEN SOURCE MEMORY

Volatility 3

Can examine supported macOS memory captures for runtime evidence, process information and other volatile artifacts.

Volatility 3
FREE LIVE RESPONSE PROCESSES

Objective-See TaskExplorer

Interactive macOS process inspection tool showing signatures, loaded dynamic libraries, open files and network connections. Useful during live-response investigations.

TaskExplorer

Linux / Unix

Incident-response collection and forensic analysis utilities for Linux servers, workstations and Unix-like systems.

01 Collect / Acquire

OPEN SOURCE LINUX TRIAGE

UAC

One of the strongest open-source choices for Unix-like incident response. Collects processes, executable hashes, logs, configuration files, user information, filesystem metadata and other evidence while respecting order-of-volatility principles.

UAC
OPEN SOURCE REMOTE COLLECTION

Velociraptor

Endpoint investigation platform suitable for remote Linux artifact collection and threat hunting across multiple hosts.

Velociraptor
OPEN SOURCE ARTIFACT COLLECTION

ArtifactCollector

Portable collection agent with prebuilt Linux versions for gathering common forensic artifacts during triage.

ArtifactCollector

02 Parse / Extract Artifacts

OPEN SOURCE TIMESTAMPS FILESYSTEM

Plaso / log2timeline

Parses large numbers of filesystem and application artifacts and combines timestamped activity into a structured forensic timeline.

Plaso Releases
OPEN SOURCE FILESYSTEM DISK

The Sleuth Kit

Command-line forensic utilities for examining filesystems, deleted entries, inode metadata and disk-image structures.

Sleuth Kit

03 Analyze / Hunt

OPEN SOURCE MEMORY

Volatility 3

Supports analysis of Linux memory captures when appropriate kernel symbol information is available.

Volatility 3
OPEN SOURCE TIMELINE COLLABORATION

Timesketch

Collaborative timeline-analysis platform for searching, filtering and investigating large forensic timelines produced from endpoint evidence.

Timesketch

Cross-Platform DFIR

Tools intentionally useful across multiple operating systems or evidence types.

OPEN SOURCE WINDOWS MAC LINUX

Velociraptor

Remote forensic collection, endpoint visibility and threat hunting across supported Windows, Linux and macOS environments.

Velociraptor
OPEN SOURCE MEMORY

Volatility 3

Cross-platform forensic framework for extracting evidence from volatile-memory captures originating from Windows, Linux and supported macOS systems.

Volatility 3
OPEN SOURCE TIMELINE

Plaso

Forensic event parsing framework used to create consolidated timelines from many artifact and filesystem sources.

Plaso
OPEN SOURCE COLLECTION

ArtifactCollector

Portable forensic collection utility with prebuilt releases for Windows, Linux and macOS.

ArtifactCollector