Skip to content
hackingtools.ai

Digital Forensics & Incident Response

Digital Forensics & Incident Response, often shortened to DFIR, is the set of tools used to collect, preserve, and examine evidence from computers, memory, and logs, and to coordinate the work when a security incident happens. It covers fast triage collection, disk and memory analysis, timeline building, and case management for response teams. Tools here help investigators work out what happened, when it started, and how far it spread, so the incident can be contained and reported.

Filters
Pricing
Platform
Open source

6 tools

  • TheHive

    TheHive

    TheHive is a freemium incident response platform used to manage security cases, alerts, and tasks for SOC, CSIRT, and CERT teams working together.

    Digital Forensics & Incident ResponseFreemium
    0
  • Plaso

    Plaso

    Plaso is a free open-source timeline tool used to extract timestamped events from disk images and logs for digital forensic investigators and analysts.

    Digital Forensics & Incident ResponseFreeOpen source
    0
  • KAPE

    KAPE is a free Windows triage tool used to collect and parse forensic artifacts quickly for government, education, and internal company incident responders.

    Digital Forensics & Incident ResponseFree
    0
  • Velociraptor

    Velociraptor

    Velociraptor is a free open-source endpoint visibility and DFIR platform for collecting and hunting host artifacts across authorized estates.

    Digital Forensics & Incident ResponseFreeOpen source
    0
  • Autopsy

    Autopsy

    Autopsy is a free open-source digital forensics platform with a graphical interface to The Sleuth Kit for disk and artifact investigation.

    Digital Forensics & Incident ResponseFreeOpen source
    0
  • Volatility

    Volatility

    Volatility is an open-source memory forensics framework for extracting digital artifacts from RAM dumps during incident response and malware analysis.

    Digital Forensics & Incident ResponseFreeOpen source
    0