Penetration testing commands for Digital Forensics

Digital forensics involves the collection, preservation, analysis, and presentation of digital evidence. It plays a critical role in incident investigations, legal proceedings, and security reviews.

NameDescriptionPrice
AndrillerSoftware utility with a collection of forensic tools for smartphones; performs read-only, non-destructive acquisitionFree
Cerbero ProfilerFile analyzer and inspectorPaid
ds_store_expExtract files from .DS_Store recursivelyFree
EML analyzerAnalyze EML files: headers, bodies, attachments; extract IOCs; identify suspicious attachmentsFree
ExifToolLibrary and CLI tool for reading, writing and editing metadata for a lot of file typesFree
extundeleteTool to recover deleted files from an ext3 or ext4 partitionFree
FibratusTool for exploration and tracing of the Windows kernelFree
ForemostCLI tool to recover files based on their headers, footers, and internal data structuresFree
ForensicMinerDFIR automation for collecting and analyzing evidenceFree
FTK ImagerInvestigate electronic devices; full disk imaging capabilities: preview and image hard drives from Windows and Linux computers, CDs, DVDs, thumb drives, and other USB; forensic image mounting: mount an image for a read-only view that leverages file explorer; preview data; RAM capturePaid
Live ForensicatorAssist forensic investigators and incidence responders in carrying out a quick live forensic investigationFree
MVTMobile Verification Toolkit; collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devicesFree
rekallVolatile memory extraction utilityFree
rekall (Fireeye fork)Fork of rekall with support for Windows 10 memory compressionFree
ResourcesExtractScans dll/ocx/exe files and extract all resources found, Windows onlyFree
shellbagsShellbag parser (Windows Registry Keys)Free
VelociraptorEndpoint visibility and collection toolFree
volatilityVolatile memory extraction utilityFree
volatility (Fireeye fork)Fork of volatility with support for Windows 10 memory compressionFree