Forensics Open Source Projects

Browse 217 Forensics open source projects, ranked by GitHub stars. Find the most popular Forensics tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 217 projects
54,230 stars

WerWolv/ImHex

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

Metrics details
Stars54,230
24,390 stars

radareorg/radare2

UNIX-like reverse engineering framework and command-line toolset

Metrics details
Stars24,390
14,317 stars

prowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Metrics details
Stars14,317
12,751 stars

mvt-project/mvt

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

Metrics details
Stars12,751
12,007 stars

kubeshark/kubeshark

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.

Metrics details
Stars12,007
11,682 stars

apsdehal/awesome-ctf

A curated list of CTF frameworks, libraries, resources and softwares

Metrics details
Stars11,682
9,272 stars

meirwah/awesome-incident-response

A curated list of tools for incident response

Metrics details
Stars9,272
5,978 stars

rmusser01/Infosec_Reference

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

Metrics details
Stars5,978
5,135 stars

cugu/awesome-forensics

⭐️ A curated list of awesome forensic analysis tools and resources

Metrics details
Stars5,135
5,083 stars

google/grr

GRR Rapid Response: remote live forensics for incident response

Metrics details
Stars5,083
4,948 stars

Hack-with-Github/Free-Security-eBooks

Free Security and Hacking eBooks

Metrics details
Stars4,948
4,254 stars

volatilityfoundation/volatility3

Volatility 3.0 development

Metrics details
Stars4,254
4,232 stars

toolswatch/blackhat-arsenal-tools

Official Black Hat Arsenal Security Tools Repository

Metrics details
Stars4,232
3,894 stars

jekil/awesome-hacking

Awesome hacking is an awesome collection of hacking tools.

Metrics details
Stars3,894
3,603 stars

WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Metrics details
Stars3,603
3,382 stars

decalage2/oletools

oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.

Metrics details
Stars3,382
3,380 stars

google/timesketch

Collaborative forensic timeline analysis

Metrics details
Stars3,380
3,261 stars

Yamato-Security/hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Metrics details
Stars3,261
3,259 stars

sleuthkit/autopsy

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.

Metrics details
Stars3,259
3,116 stars

sleuthkit/sleuthkit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

Metrics details
Stars3,116
2,960 stars

mikeroyal/Digital-Forensics-Guide

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

Metrics details
Stars2,960
2,919 stars

JohnHammond/ctf-katana

This repository aims to hold suggestions (and hopefully/eventually code) for CTF challenges. The "project" is nicknamed Katana.

Metrics details
Stars2,919
2,877 stars

frankwxu/digital-forensics-lab

Free hands-on digital forensics labs for students and faculty

Metrics details
Stars2,877
2,573 stars

danieldurnea/FBI-tools

🕵️ OSINT Tools for gathering information and actions forensics 🕵️

Metrics details
Stars2,573
2,508 stars

mesquidar/ForensicsTools

A list of free and open forensics analysis tools and other resources

Metrics details
Stars2,508
2,186 stars

dreddsa5dies/goHackTools

Hacker tools on Go (Golang)

Metrics details
Stars2,186
2,119 stars

log2timeline/plaso

Super timeline all the things

Metrics details
Stars2,119
1,880 stars

stuxnet999/MemLabs

Educational, CTF-styled labs for individuals interested in Memory Forensics

Metrics details
Stars1,880
1,878 stars

m14r41/PentestingEverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...

Metrics details
Stars1,878
1,870 stars

Srinivas11789/PcapXray

:snowflake: PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction

Metrics details
Stars1,870
1,778 stars

PabloLec/RecoverPy

Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

Metrics details
Stars1,778
1,773 stars

simsong/tcpflow

TCP/IP packet demultiplexer. Download from:

Metrics details
Stars1,773
1,586 stars

den4uk/andriller

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.

Metrics details
Stars1,586
1,469 stars

obsidianforensics/hindsight

Web browser forensics for Google Chrome/Chromium

Metrics details
Stars1,469
1,430 stars

cisagov/Sparrow

Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

Metrics details
Stars1,430
1,407 stars

tclahr/uac

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

Metrics details
Stars1,407
1,342 stars

cecio/USBvalve

Expose USB activity on the fly

Metrics details
Stars1,342
1,249 stars

ForensicArtifacts/artifacts

Digital Forensics artifact repository

Metrics details
Stars1,249
1,221 stars

rng70/TryHackMe-Roadmap

a list of 350+ Free TryHackMe rooms to start learning cybersecurity with THM

Metrics details
Stars1,221
1,183 stars

snovvcrash/usbrip

Tracking history of USB events on GNU/Linux

Metrics details
Stars1,183
1,098 stars

AvillaDaniel/AvillaForensics

Avilla Forensics FREE

Metrics details
Stars1,098
1,065 stars

ydkhatri/mac_apt

macOS (& ios) Artifact Parsing Tool

Metrics details
Stars1,065
1,063 stars

thehackingsage/hackdroid

Security Apps for Android

Metrics details
Stars1,063
791 stars

google/turbinia

Automation and Scaling of Digital Forensics Tools

Metrics details
Stars791
788 stars

PaulNorman01/Forensia

Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase.

Metrics details
Stars788
786 stars

kai5263499/osx-security-awesome

A collection of OSX and iOS security resources

Metrics details
Stars786
784 stars

z0m31en7/Uscrapper

Uscrapper Vanta: Dive deeper into the web with this powerful open-source tool. Extract valuable insights with ease and efficiency, from both surface and deep web sources. Empower your data mining and analysis with Vanta's advanced capabilities. Fast, reliable, and user-friendly, Uscrapper Vanta is the ultimate choice for researchers and analysts.

Metrics details
Stars784
777 stars

bluecapesecurity/PWF

Practical Windows Forensics Training

Metrics details
Stars777
773 stars

williballenthin/python-evtx

Pure Python parser for Windows Event Log files (.evtx)

Metrics details
Stars773
746 stars

gaulliath/operative-framework

operative framework is a rust investigation OSINT framework, you can interact with multiple targets, execute multiple modules, create links with target, export rapport to PDF file, add note to target or results, interact with RESTFul API, write your own modules.

Metrics details
Stars746
725 stars

ashemery/LinuxForensics

Everything related to Linux Forensics

Metrics details
Stars725
722 stars

TonyPhipps/SIEM

SIEM Tactics, Techiques, and Procedures

Metrics details
Stars722
709 stars

Yamato-Security/EnableWindowsLogSettings

Documentation and scripts to properly enable Windows event logs.

Metrics details
Stars709
702 stars

cristianzsh/forensictools

Collection of forensic tools

Metrics details
Stars702
689 stars

CScorza/OSINT-FORENSICS-MOBILE

Tools OSINT MOBILE

Metrics details
Stars689
672 stars

Nhoya/gOSINT

OSINT Swiss Army Knife

Metrics details
Stars672
668 stars

alphaSeclab/awesome-forensics

Awesome Forensics Resources. Almost 300 open source forensics tools, and 600 blog posts about forensics.

Metrics details
Stars668
661 stars

stuhli/awesome-event-ids

Collection of Event ID ressources useful for Digital Forensics and Incident Response

Metrics details
Stars661
633 stars

awslabs/aws-security-automation

Collection of scripts and resources for DevSecOps and Automated Incident Response Security

Metrics details
Stars633
629 stars

Netflix-Skunkworks/diffy

:no_entry: (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.

Metrics details
Stars629
1-60 of 217 projects
Get A Weekly Email With Trending Forensics Projects
Stay updated on Forensics plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.