AVML - A portable volatile memory acquisition tool for Linux.
ArtifactExtractor - Extract common Windows artifacts from source images and VSCs.
artifactcollector - A customizable agent to collect forensic artifacts on any Windows, macOS or Linux system.
Redline - Free endpoint security tool from FireEye.
Loki - Simple IOC and Incident Response Scanner.
Supports md5/sha1/sha256 hashes, literal/wildcard strings, regular expressions and YARA rules
Fastfinder - Fast customisable cross-platform suspicious file finder.
UAC - UAC (Unix-like Artifacts Collector) is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
POFR - The Penguin OS Flight Recorder collects, stores and organizes for further analysis process execution, file access and network/socket endpoint data from the Linux Operating System.
osquery - SQL powered operating system analytics.
mig - Distributed & real time digital forensics at the speed of the cloud.
Linux Expl0rer - Easy-to-use live forensics toolbox for Linux endpoints written in Python & Flask.
grr - GRR Rapid Response: remote live forensics for incident response.
IPED - Indexador e Processador de Evidências Digitais - Brazilian Federal Police Tool for Forensic Investigations.
turbinia - Turbinia is an open-source framework for deploying, managing, and running forensic workloads on cloud platforms.
:star: The Sleuth Kit - Tools for low level forensic analysis.
TAPIR - TAPIR (Trustable Artifacts Parser for Incident Response) is a multi-user, client/server, incident response framework.
PowerForensics - PowerForensics is a framework for live disk forensic analysis.
Laika BOSS - Laika is an object scanner and intrusion detection system.
Kuiper - Digital Investigation Platform.
IntelMQ - IntelMQ collects and processes security feeds.
hashlookup-forensic-analyser - A tool to analyse files from a forensic acquisition to find known/unknown hashes from hashlookup API or using a local Bloom filter.
dexter - Dexter is a forensics acquisition framework designed to be extensible and secure.
Tsurugi Linux - Linux distribution for forensic analysis.
SANS Investigative Forensics Toolkit (sift) - Linux distribution for forensic analysis.
Remnux - Distro for reverse-engineering and analyzing malicious software.
bitscout - LiveCD/LiveUSB for remote forensic acquisition and analysis.
:star: Artifact Repository - Machine-readable knowledge base of forensic artifacts.
DFIR.Training - Database of forensic resources focused on events, tools and more.
Offers lists of certifications, books, blogs, challenges and more
AboutDFIR – The Definitive Compendium Project - Collection of forensic resources for learning and research.
Curated list of awesome free (mostly open source) forensic analysis tools and resources.