Digital Forensics Resources
Curated collection of tools, courses, research papers, and guides to help you master digital forensics and cybersecurity
Learning Resources
Explore our curated collection of forensics and cybersecurity resources
Featured Resources
Stark 4n6 START.ME
Comprehensive List of Forensic Resources including tools, articles, courses, and useful links for digital forensics enthusiasts and professionals.
The Evidence Locker
A DFIR Image Compendium. Come and find links and information about publicly available test data for the DFIR community.
All Resources
Autopsy Digital Forensics
Open source digital forensics platform and GUI for The Sleuth Kit and other digital forensics tools. Autopsy is used worldwide by law enforcement and corporate entities.
Memory Forensics with Volatility
The world’s most widely used memory forensics platform.
The Sleuth Kit
The Sleuth Kit® (TSK) is a library and collection of command line tools that allow you to investigate disk images
Kroll Artifact Parser and Extractor (KAPE)
KAPE is an efficient and highly configurable triage program that will target essentially any device or storage location, find forensically useful artifacts, and parse them within a few minutes
SANS Digital Forensics Research
Latest research papers and whitepapers on digital forensics techniques, malware analysis, and incident response methodologies.
Malware and Network Traffic Analysis
Website focusing on network traffic analysis and malware analysis. Contains pcap files, malware samples, and detailed analysis tutorials.
Wireshark
Wireshark is a network protocol analyzer that captures and displays network traffic in real-time.
Hayabusa
Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan. Hayabusa means "peregrine falcon" in Japanese and was chosen as peregrine falcons are the fastest animal in the world, great at hunting and highly trainable
FTK Imager
Free tool to preview recoverable data from a disk and create forensic images of computer data without affecting the original evidence.
Arsenal Image Mounter
Arsenal Image Mounter is the first and only open source solution for mounting the contents of disk images as complete disks in Windows.
Velociraptor
Velociraptor is a tool for collecting host based state information using The Velociraptor Query Language (VQL) queries.
CyberChef
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.
SANS Institue
Launched in 1989 as a cooperative for information security thought leadership, SANS (SysAdmin, Audit, Network, Security) Institute is the largest and most trusted provider of cybersecurity training, certifications, programs, and resources in the world. Our ongoing mission is to empower current and future cybersecurity practitioners with practical skills and knowledge that make the digital world safer, and to support the global cybersecurity community at every stage of their journey.
Scientific Working Group on Digital Evidence (SWGDE)
The Scientific Working Group on Digital Evidence is composed of members approved and voted in from all levels of government, the legal community, private industry, and academia involved in the digital and multimedia forensic profession. All prospective members must attend two Scientific Working Group on Digital Evidence meetings as a guest to be considered for membership
Forensics Linux Distributions
-
Tsurugi Linux DFIR open source project with advanced digital forensic analysis and OSINT tools -
SIFT Workstation SANS Investigative Forensics Toolkit for incident response and digital forensics -
Parrot Security Lightweight distribution with comprehensive digital forensics and incident response tools -
CAINE Computer Aided INvestigative Environment for digital forensics investigations -
DEFT Linux Digital Evidence & Forensics Toolkit for computer forensics and incident response -
Evanole VM Virtual machine designed for digital forensics education and training
Want to Contribute?
Know a great resource that should be listed here? We're always looking to expand our collection with high-quality learning materials and tools.
Suggest a Resource