Penetration testing commands for digital forensics

NameDescriptionCodePriceTags
FibratusTool for exploration and tracing of the Windows kernelhttps://github.com/rabbitstack/fibratusFreedigital_forensics
ForemostCLI tool to recover files based on their headers, footers, and internal data structureshttps://sourceforge.net/projects/foremost/Freedigital_forensics
ForensicMinerDFIR automation for collecting and analyzing evidencehttps://github.com/securityjoes/ForensicMinerFreedigital_forensics
FTK ImagerInvestigate electronic devices; full disk imaging capabilities: preview and image hard drives from Windows and Linux computers, CDs, DVDs, thumb drives, and other USB; forensic image mounting: mount an image for a read-only view that leverages file explorer; preview data; RAM capturePaiddigital_forensics
MVTMobile Verification Toolkit; collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS deviceshttps://github.com/mvt-project/mvtFreedigital_forensics
ResourcesExtractScans dll/ocx/exe files and extract all resources found, Windows onlyFreedigital_forensics
shellbagsShellbag parser (Windows Registry Keys)https://github.com/williballenthin/shellbagsFreedigital_forensics
VelociraptorEndpoint visibility and collection toolhttps://github.com/Velocidex/velociraptorFreedigital_forensics
volatilityVolatile memory extraction utilityhttps://github.com/volatilityfoundation/volatilityFreedigital_forensics
AndrillerSoftware utility with a collection of forensic tools for smartphones; performs read-only, non-destructive acquisitionhttps://github.com/den4uk/andrillerFreedigital_forensics
Cerbero ProfilerFile analyzer and inspectorPaiddigital_forensics
ds_store_expExtract files from .DS_Store recursivelyhttps://github.com/lijiejie/ds_store_expFreedigital_forensics
EML analyzerAnalyze EML files: headers, bodies, attachments; extract IOCs; identify suspicious attachmentshttps://github.com/ninoseki/eml_analyzerFreedigital_forensics
extundeleteTool to recover deleted files from an ext3 or ext4 partitionhttps://sourceforge.net/projects/extundelete/Freedigital_forensics
rekallVolatile memory extraction utilityhttps://github.com/google/rekallFreedigital_forensics
rekall (Fireeye fork)Fork of rekall with support for Windows 10 memory compressionhttps://github.com/fireeye/win10_rekallFreedigital_forensics
Live ForensicatorAssist forensic investigators and incidence responders in carrying out a quick live forensic investigationhttps://github.com/Johnng007/Live-ForensicatorFreedigital_forensics
volatility (Fireeye fork)Fork of volatility with support for Windows 10 memory compressionhttps://github.com/fireeye/win10_volatilityFreedigital_forensics
ExifToolLibrary and CLI tool for reading, writing and editing metadata for a lot of file typeshttps://sourceforge.net/projects/exiftool/Freedigital_forensics