Digital Forensics & Incident Response
Digital Forensics & Incident Response, often shortened to DFIR, is the set of tools used to collect, preserve, and examine evidence from computers, memory, and logs, and to coordinate the work when a security incident happens. It covers fast triage collection, disk and memory analysis, timeline building, and case management for response teams. Tools here help investigators work out what happened, when it started, and how far it spread, so the incident can be contained and reported.

TheHive
TheHive is a freemium incident response platform used to manage security cases, alerts, and tasks for SOC, CSIRT, and CERT teams working together.
Digital Forensics & Incident ResponseFreemium
Plaso
Plaso is a free open-source timeline tool used to extract timestamped events from disk images and logs for digital forensic investigators and analysts.
Digital Forensics & Incident ResponseFreeOpen sourceKAPE
KAPE is a free Windows triage tool used to collect and parse forensic artifacts quickly for government, education, and internal company incident responders.
Digital Forensics & Incident ResponseFree
Velociraptor
Velociraptor is a free open-source endpoint visibility and DFIR platform for collecting and hunting host artifacts across authorized estates.
Digital Forensics & Incident ResponseFreeOpen source
Autopsy
Autopsy is a free open-source digital forensics platform with a graphical interface to The Sleuth Kit for disk and artifact investigation.
Digital Forensics & Incident ResponseFreeOpen source
Volatility
Volatility is an open-source memory forensics framework for extracting digital artifacts from RAM dumps during incident response and malware analysis.
Digital Forensics & Incident ResponseFreeOpen source