Forensics & IR
Memory, disk, hunting artifacts, and incident response.
Autopsy
ForensicsGUI digital forensics platform built on The Sleuth Kit for disk images, timelines, keyword search, and artifact parsing.
ExifTool
ForensicsRead and write metadata in images, documents, and media — GPS, camera info, author fields, and hidden tags.
Foremost
ForensicsFile carving tool that recovers files from disk images by header/footer signatures when filesystem metadata is missing.
Steganography
ForensicsSteganography and hidden-data extraction for CTF and forensics: images, audio, files, and embedded archives.
The Sleuth Kit
ForensicsCLI forensic toolkit to analyze disk images — partition tables, inode listing, and file carving without GUI.
Velociraptor
ForensicsEndpoint visibility and digital forensic platform with VQL for hunting, collections, and incident response at scale.
Volatility
ForensicsMemory forensics framework for extracting processes, credentials, and malware artifacts from RAM dumps.
YARA
ForensicsPattern matching language to identify malware families, IOCs, and suspicious byte sequences in files and memory.