A neutral, factual directory of the software, hardware and open-source tools used across digital forensics and incident response: what each product is, who makes it, and where to learn more, with links to our independent reviews where we have published one. Listings are alphabetical and never ranked; inclusion is editorial and free.
What the directory lists
142 digital forensics and incident response tools from 81 vendors and open-source projects, in 14 categories. Entries are neutral facts (what the tool is, who makes it, how it is deployed and licensed) with links to Forensic Focus reviews where one exists. Products are listed alphabetically within each category; the directory carries no scores, rankings or feature comparisons. Inclusion is editorial and free. Data as of 2026-09-02.
Acquisition, imaging & hardware (20)
Arsenal Image Mounter (Arsenal Image Mounter, open source); Atola Insight Forensic (Atola Technology); Atola TaskForce 2 (Atola Technology); Ditto DX Forensic FieldStation (CRU (WiebeTech)); eMMC-NAND Reconstructor (Rusolut); Exterro FTK Imager (Exterro); Falcon-NEO2 (Logicube); OpenText Forensic TX2 Imager (OpenText Tableau Forensic); OpenText Tableau Forensic TD4 Duplicator (OpenText Tableau Forensic); PC-3000 Express (ACE Lab); PC-3000 Flash (ACE Lab); PC-3000 Mobile PRO (ACE Lab); PC-3000 Portable PRO (ACE Lab); SuperImager Plus 8 inch T4 Portable Forensic Imaging Unit (MediaClone); SuperImager Plus Desktop 8 NVMe U.2 Ports Standalone Forensic Imaging Unit (MediaClone); USB WriteBlocker (CRU (WiebeTech)); Visual NAND Reconstructor (VNR) (Rusolut); WiebeTech Forensic UltraDock FUDv6 (CRU (WiebeTech)); WriteProtect-DESKTOP (Logicube); WriteProtect-PORTABLE (Logicube).
Computer & disk forensics (33)
Autopsy / The Sleuth Kit (Autopsy / The Sleuth Kit, open source); Belkasoft Remote Acquisition (Belkasoft); Belkasoft Triage (Belkasoft); Belkasoft X Forensic (Belkasoft); Blade (Digital Detective); Bulk Extractor (Bulk Extractor, open source); DBF | Database Forensic Analysis System (SalvationDATA); E3 Forensic Platform (Paraben Corporation); Exterro FTK Enterprise (Exterro); Exterro FTK Forensic Toolkit (Exterro); Exterro FTK Lab (Exterro); FEX Triage (GetData Forensics); Forensic Explorer (FEX) (GetData Forensics); Hibernation Recon (Arsenal Recon); HstEx (Digital Detective); Magnet Automate (Magnet Forensics); Magnet Axiom (Magnet Forensics); Magnet Axiom Cyber (Magnet Forensics); Magnet Nexus (Magnet Forensics); Mount Image Pro (GetData Forensics); NetAnalysis (Digital Detective); OpenText Endpoint Investigator (OpenText); OpenText Forensic (OpenText); OSForensics (PassMark Software); PALADIN (SUMURI); RECON ITR (SUMURI); RECON LAB (SUMURI); Registry Recon (Arsenal Recon); TALINO Forensic Workstations (SUMURI); Truxton (Truxton Forensics); WinHex (X-Ways Software Technology); X-Ways Forensics (X-Ways Software Technology); X-Ways Investigator (X-Ways Software Technology).
eDiscovery & investigative analytics (5)
Intella Connect (Vound); Intella Pro (Vound); Nuix Neo (Nuix); Nuix Workstation (Nuix); RelativityOne (Relativity).
Email & communications forensics (3)
Aid4Mail (Fookes Software); Forensic Email Collector (Metaspike); Forensic Email Intelligence (Metaspike).
Enterprise & cloud DFIR (5)
Binalyze AIR (Binalyze); Cyber Triage (Sleuth Kit Labs); Darktrace / Forensic Acquisition & Investigation (Darktrace); Surge Collect (Volexity); Volexity Volcano (Volexity).
Image & video forensics (9)
Amped Authenticate (Amped Software); Amped FIVE (Amped Software); Amped Replay (Amped Software); CaseScan (CaseScan); LEAP (T3K.AI); Magnet Griffeye (Magnet Forensics); Magnet Verify (Magnet Forensics); S21 VisionX (Semantics 21); VIP3.0 | Video Investigation Portable 3.0 (SalvationDATA).
Lab, case & threat-intel management (5)
Lima Forensic Case Management (IntaForensics); MISP (MISP, open source); Monolith (Monolith Forensics); SAFE (Tracker Products); TheHive / Cortex (TheHive / Cortex, open source).
Memory forensics (2)
MemProcFS (MemProcFS, open source); Volatility 3 (Volatility 3, open source).
Mobile & device forensics (18)
AFA9500 | Mobile Forensics Solution (SalvationDATA); ALEAPP (ALEAPP, open source); Camera Ballistics (Compelson); Cellebrite Inseyets (Cellebrite); Cellebrite UFED (Cellebrite); Evanole VM (Hexordia); iLEAPP (iLEAPP, open source); iVe Ecosystem (Berla); MD-LIVE (GMDSOFT); MD-NEXT (GMDSOFT); MD-RED (GMDSOFT); MOBILedit Cloud Forensic (Compelson); MOBILedit Forensic (Compelson); Oxygen Forensic Detective (Oxygen Forensics); Oxygen Remote Explorer (Oxygen Forensics); Oxygen Review Center (Oxygen Forensics); XAMN (MSAB); XRY (MSAB).
Network forensics (2)
Wireshark (Wireshark, open source); Zeek (Zeek, open source).
OSINT & link analysis (9)
Fivecast ONYX (Fivecast); Horizon (ShadowDragon); Hunchly (Maltego Technologies); Maltego Graph (Maltego Technologies); Maltego Search (Maltego Technologies); Page Vault Browser (Page Vault); ProofSnap (ProofSnap); SocialNet (ShadowDragon); Workbench (Skopenow).
Password recovery & decryption (8)
Elcomsoft Distributed Password Recovery (ElcomSoft); Elcomsoft iOS Forensic Toolkit (ElcomSoft); Elcomsoft Phone Breaker (ElcomSoft); Magnet Graykey (Magnet Forensics); Magnet Graykey Fastrak (Magnet Forensics); Passware Kit Forensic (Passware); Passware Kit Mobile (Passware); Passware Kit Ultimate (Passware).
Timeline, log & artefact analysis (10)
Chainsaw (Chainsaw, open source); CyberChef (CyberChef, open source); Dissect (Dissect, open source); Eric Zimmerman Tools (EZ Tools) (Eric Zimmerman Tools (EZ Tools), open source); Hayabusa (Hayabusa, open source); Plaso / log2timeline (Plaso / log2timeline, open source); RegRipper 4.0 (RegRipper 4.0); Sigma (SigmaHQ) (Sigma (SigmaHQ), open source); Timesketch (Timesketch, open source); YARA / YARA-X (YARA / YARA-X, open source).
Triage & endpoint collection (13)
ADF PRO (ADF Solutions); Ballistic Imager (Detego Global); Cyacomb Examiner Plus (Cyacomb); DFIR ORC (DFIR ORC, open source); Digital Evidence Investigator (DEI) (ADF Solutions); Field Triage (Detego Global); GRR Rapid Response (GRR Rapid Response, open source); KAPE (KAPE); Magnet RESPONSE (Magnet RESPONSE); Mobile Device Investigator (MDI) (ADF Solutions); UAC (Unix-like Artifacts Collector) (UAC (Unix-like Artifacts Collector), open source); Unified Digital Forensics Platform (Detego Global); Velociraptor (Velociraptor, open source).
More DFIR career tools
- DFIR Salary Explorer: advertised pay by country, role and seniority
- DFIR Skills Demand Explorer: the tools and certifications employers ask for
- DFIR Training Finder: courses and certifications ranked by employer demand
- Practice and CTF Directory: evidence datasets, labs and challenges to build skills on
- Tool Release Tracker: latest releases across the open-source DFIR toolbox