A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.
-
Updated
Oct 4, 2025 - Python
A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.
MacOS forensic acquisition made simple
Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS.
Automatically create iSCSI targets for all drives except for a boot device
Cryptocurrency Discovery and Triage Tool - Identify multiple cryptocurrency addresses and transactions from various wallet applications!
A deployment and testing platform for Velociraptor's client artifacts
Yerel ağlarda anomaly detection, saldırı tespiti ve adli bilişim analizi yapan tek Pythontkinter tabanlı açık kaynak araç. Özelleştirilebilir imza veritabanıyla Türkiye odaklı tehditleri yakalar!
AWMFA - Automated Windows Memory Forensics Analysis. Python automation framework for Volatility 2 that streamlines memory analysis. Features: automated plugin execution with threading, intelligent threat detection using 28+ heuristics, no deep Windows internals knowledge required, multi-format reports (TXT/HTML/PDF).
A forensic command-line tool for deep analyzing PDF files
Convert Kape Files to DFIR-ORC configurations
bfcpf stands for "Brute Force CPF" and it is a CLI tool that breaks a partial CPF, finding all valid ones within the pattern given by the user.
OpenRelik ertools worker
Unified cases, seamless integrations
Minimalist Collaborative Malware DB Management
Collaborative Forensic Collections Manager
TruxTrace is a Linux user simulation tool that emulates realistic command-line behavior for single and multiple users. It’s designed for learning, testing, and digital forensics, generating artifacts like logs and histories to replicate real-world usage scenarios.
YaFT2 - Yet Another Forensic Tool
Wuodan is a command-line tool designed for efficiently searching through files and directories for strings or regular expressions
This tool monitors Velociraptor's syslog messages for specific actions performed by users within the Velociraptor DFIR platform. When certain patterns are detected, it sends detailed email notifications to designated recipients, providing enhanced visibility into user activities and potential security events.
Add a description, image, and links to the dfir-tools topic page so that developers can more easily learn about it.
To associate your repository with the dfir-tools topic, visit your repo's landing page and select "manage topics."