Apps tagged with 'dfir'

All apps in Apps tagged with 'dfir' category. Use the filters below to narrow down your search. 
Copy a direct link to this comment to your clipboard
  1. Matano icon
     2 likes

    Matano is an open source security lake platform for AWS. It lets you ingest petabytes of security and log data from various sources, store and query them in a data lake, and create Python detections as code for realtime alerting.

    Cost / License

    Platforms

    • Linux
    • Self-Hosted
    Matano screenshot 1
    Matano screenshot 1
    Matano screenshot 2
    9 alternatives
  2. Magnet Acquire lets digital forensic examiners quickly and easily acquire forensic images of any iOS or Android device, hard drive, and removable media — and is available at no cost to the forensic community.

    Cost / License

    • Free
    • Proprietary

    Platforms

    • Windows
    1 alternatives
  3. UFADE icon
     2 likes

    Extract files from iOS devices on Linux and MacOS. Mostly a wrapper for pymobiledevice3. Creates iTunes-style backups and "advanced logical backups".

    Cost / License

    Platforms

    • Windows
    • Linux
    • Mac
    2 alternatives
  4. FastFinder is a lightweight tool made for threat hunting, live forensics and triage on both Windows and Linux Platforms. It is focused on endpoint enumeration and suspicious file finding based on various criterias:

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Windows
    • Linux
    FastFinder screenshot 1
    4 alternatives
  5. Collect data from the widest range of digital devices.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Windows
    1 alternatives
  6. RECON ITR brings both Bootable and Live imaging options into one. An indispensable tool for anyone who needs to image and capture data from all Intel macOS computers.

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Mac
    • Windows
    Main interface
    Imager window
    Triage window
    3 alternatives
  7. LLIMAGER icon
     Like

    LLIMAGER was designed to address the evolving challenges of macOS forensic imaging. Specifically, it was created in response to the limitations of existing "dead box" solutions and the increasingly stringent security measures implemented by Apple in successive macOS...

    Cost / License

    • Paid
    • Proprietary

    Platforms

    • Mac
    Main interface
    Disk image creation
    Targeted acquisition
    +1
    Best practices checklist
    3 alternatives
  8. Program written in python that attempts to reconstruct and recover data from disks or disk images. Recommended for use from disk images, works well with ddrescue. Currently only works on ntfs filesystems. Can be ran on any operating system that supports python.

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
    RecuperaBit screenshot 1
    56 alternatives
  9. As the name implies, this is a hex editor. It aims to be a good general-purpose hex editor and to have a wide selection of features for analysing and annotating binary file formats.

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    11 alternatives
  10. SpectX icon
     Like

    SpectX is a distributed log-parser and query engine that works across multiple log sources like log servers, AWS, ELK, etc. It does not ingest any data but creates a virtual table from the raw data.

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    11 alternatives