Digital Forensics Tools
Practical forensics references for incident responders. Find artefacts fast, build timelines, preserve evidence correctly, and document chain of custody — all without leaving your browser.
Artefact Reference
Windows Forensics Artefact Finder
Select your investigation goal — lateral movement, persistence, credential theft, data exfil — and get exact file paths, registry keys, and extraction commands. No more Googling during an incident.
Find artefacts →Linux Forensics Artefact Guide
Every forensically relevant location on Linux — auth.log, bash history, cron, systemd journal, /proc, SSH artefacts, and application logs. Organised by investigation goal with exact extraction commands.
View Linux artefacts →Browser Forensics Reference
Forensic evidence in Chrome, Firefox, Edge, and Safari. Exact file paths, SQLite queries, and what each artefact proves. Covers history, downloads, credentials, cache, extensions, and sync data.
Browse artefacts →Windows Registry Forensics Map
Every forensically relevant registry key — ShimCache, AmCache, UserAssist, RecentDocs, MuiCache, Run keys, mounted devices. Exact paths, extraction commands, and what each key proves.
Explore registry →Forensic Tool Reference
Every essential free forensics tool — what it does, when to use it, key commands, and output format. Covers acquisition, analysis, timeline, network, and memory tools. Filterable by task.
Browse tools →Memory Acquisition Guide
Step-by-step volatile memory acquisition for Windows and Linux. Which tools to use, how to verify integrity, chain of custody for memory dumps, and VM vs physical acquisition differences.
View guide →Investigation Support
Forensic Timeline Builder
Paste mixed log entries — Windows events, Sysmon, firewall, proxy. The tool sorts chronologically, maps events to MITRE techniques, labels attack phases, and generates a structured IR timeline.
Build timeline →Chain of Custody Generator
Generate a legally formatted chain of custody document for digital evidence. Enter incident details, evidence items with hash values, and personnel. Output is formatted for Indian legal proceedings.
Generate document →