100 Free Security Tools
For ethical hackers and forensic investigators
INSIDE CLOUD
100 Free Security Tools
For ethical hackers and forensic investigators
1. Autopsy - Open source digital forensics platform to analyze hard drives and smart phones
[Link]
2. EnCase - Commercial computer forensics software for e-discovery and investigations by OpenText
[Link]
3. AccessData (FTK) - Forensic toolkit computer investigation software by AccessData
[Link]
4. X-Ways Forensics - Integrated computer forensics software by X-Ways Software Technology [Link]
[Link]/forensics/
5. Sleuth Kit - Open source digital forensics tools for analyzing disk images and file systems
[Link]
6. Volatility - Memory forensics framework to analyze volatile memory dumps and artifacts
[Link]
7. Wireshark - Network protocol analyzer useful for network forensics and traffic analysis
[Link]
8. Cellebrite UFED - Commercial mobile forensic software to extract data from phones and tablets
[Link]
9. Email Collector - Tool to collect and analyze email data during investigations
[Link]
10. Forensics (DFF) - Digital forensics framework, an open source platform for investigations
[Link]
11. Magnet AXIOM - Commercial digital investigations platform from Magnet Forensics
[Link]
12. Oxygen Detective - Cloud extraction tool for investigations involving cloud services [Link]
[Link]/en/oxygen-detective
13. OSForensics - Specialized forensics tools for Microsoft systems from PassMark
[Link]
14. NetworkMiner - Open source network forensic analyzer useful for investigating traffic
[Link]
15. RegRipper - Tool to parse Windows registry files and dig for useful data
[Link]
16. Bulk Extractor - Scans disk images and extract interesting bits of data
[Link]
17. Ghiro - Web site screenshots and analysis for forensic investigations [Link]
18. Scalpel - File carver which recovers files based on headers and footers
[Link]
19. HxD - Hex editor useful for analyzing raw disk and memory dumps [Link]
20. TestDisk - Data recovery tool, useful when file systems get corrupted
[Link]
21. PhotoRec - Recovery tool specifically focused on photos and media files
[Link]
22. CAINE - Italian GNU/Linux live distribution with many forensics tools [Link]
23. Axiom Cyber - Commercial digital forensics and incident response platform
[Link]
24. Belkasoft Evidence - Commercial all-in-one forensics solution for Windows, mobile etc
[Link]
25. Fibratus - Tool to explore and trace Windows kernel activity and data
[Link]
26. Autopsy Browser - GUI interface for autopsy digital forensics platform
[Link]
27. Kali Linux - Penetration testing Linux distribution with many useful security tools [Link]
28. DEFT - Linux distribution configured specifically for computer forensics [Link]
29. Volatility Framework - Advanced memory forensics framework with plugins and APIs
[Link]
30. PyFlag - Legacy Australian forensic and log analysis GUI platform [Link]
100 Free Security Tools
For ethical hackers and forensic investigators
31. Plaso (log2timeline) - Extract timestamps from various logs and aggregate timeline
[Link]
32. TSK (The Sleuth Kit) - File system and disk analysis tools originally focussed on NTFS
[Link]
33. Redline - Host investigations and malware analysis tool by FireEye
[Link]
34. Snort - Open source intrusion detection and network monitoring system [Link]
35. Tcpdump - Capture and analyze network traffic on Unix-like systems [Link]
36. Ngrep - Search within network traffic payloads like grep for text streams [Link]
37. dcfldd - Disk cloning and forensics tool, version of dd with hashing [Link]
38. Wireshark - Network traffic analyzer useful for network forensics [Link]
39. SIFT (SANS) - Ubuntu-based distribution for forensic analysis [Link]
[Link]/community/downloads
40. Paladin - USB image mounted as virtual drive with write-protection
[Link]
41. CAINE Live - Self-contained bootable forensic environment [Link]
42. XRY (XAMN) - Commercial mobile forensic software to analyze phones [Link]
43. BlackLight - Powerful Windows-based forensics analysis platform
[Link]
44. WinHex - Hex editor, particularly helpful for low-level analyzing raw data [Link]
[Link]/winhex/
45. Access FTK Imager - Disk and volume imaging software from AccessData [Link]
download
46. DC3DD - Improved version of dd for forensics, handles errors better [Link]
Crime-Center/DC3-DD
47. Raptor - Validation tool to verify integrity of forensic copies [Link]
48. EnCase Imager - Disk imaging tool from Guidance Software [Link]
imager
49. Guymager - Open source disk cloning and imaging tool for Linux [Link]
50. Scalpel - File carver recovering files based on header/footer signatures
[Link]
51. Extundelete - Used to recover deleted files from mountable images [Link]
52. Xplico - Network forensics tool that rebuilds sessions from traffic [Link]
53. Foremost - File carving utility to recover files using header/footer definitions
[Link]
54. Hunchback - High speed packet capture and transmission tool [Link]
55. Autopsy Tools - Plugins and tools used alongside Autopsy forensics GUI
[Link]
56. OSForensics Imager - Hardware write block tool for connecting devices
[Link]
57. Dislocker - Decrypts Bitlocker encrypted volumes with mounted filesystem
[Link]
58. Bulk Extractor - Extract forensically interesting information from disk images
[Link]
59. SANS SIFT - Ubuntu-derived distro for digital forensic analysis [Link]
[Link]/community/downloads
60. Live View - Volatile memory analysis tool for Windows systems [Link]
61. LRR - Tool for viewing Windows artifacts including LNK files
[Link]
62. NTFS-3G - Open source cross-platform NTFS driver with write support
[Link]
63. WindowsSCOPE - Registry analysis tool for dumped SYSTEM/SAM/SECURITY hives
[Link]
64. Volafax - Forensic system suited for investigations over remote areas
[Link]
100 Free Security Tools
For ethical hackers and forensic investigators
65. Amcache Parser - Recovers data from Windows 10 [Link] artifact file
[Link]
66. The Hive - Web interface offering querying capabilities for hive files [Link]
67. GRR Rapid Response - Incident response framework focused on remote live forensics
[Link]
68. Rekall - Advanced forensic memory analysis framework powered by Python [Link]
[Link]/
69. DFF - Open source digital forensics framework and platform written in Python
[Link]
70. SSDeep - Fuzzy hashing tool used for malware clustering and piecewise comparisons [Link]
[Link]/ssdeep/[Link]
71. KAPE - Target acquisition tool focused on enterprise lines of business [Link]
72. USB Write Blocker - Hardware ensuring write protection when imaging USB devices
73. AIL - Network and host monitoring system for identification of intrusions [Link]
management/products-services/[Link]
74. Rifiuti2 - Analyzes Windows Recycle Bin INFO2 files and recovers filenames
[Link]
75. VolDiff - Compares memory images and highlights differences for analysis [Link]
76. WinAudit - Scans Windows systems and reports changes from baseline [Link]
77. hfind - Carves unallocated space and extracts hidden/deleted data into files
[Link]
78. Yara - Pattern matching tool aimed at malware researchers
79. Checkm8 - Jailbreaking tool extracting data from passcode locked iOS devices [Link]
80. Olefile - Python package for parsing OLE and Office documents [Link]
81. Pyew - Python tool for malware analysis static and dynamic [Link]
82. E01 Examiner - Software utility for mounting EnCase evidence file formats [Link]
83. USBDeview - Handy Windows tool listing all USB devices ever connected
[Link]
84. Autopsy - iPhone - Autopsy module adds iOS analysis functionality
[Link]
85. DC3-MWCP - Collection of tools for forensic enterprise analysis from DC3 [Link]
catalog/
86. X-Ways Imager - Disc imaging tool to create forensic images, integrated into X-Ways Forensics
[Link]
87. Memoryze - Memory acquisition and analysis tool for Windows systems
[Link]
88. EVTExtract - Automated parsing modules for Windows event log records
[Link]
89. Speedit - Detection and analysis of spyware, keyloggers, trojans etc [Link]
90. SniffPass - Sniffs passwords and other sensitive information from a network
[Link]
91. Nmap - Network scanning and host discovery tool helpful for reconnaissance [Link]
92. OSINT Framework - Gathering publicly available online data regarding targets [Link]
93. Recon-ng - Web based open source reconnaissance framework [Link]
94. OSINT-SPY - Performs extensive reconnaissance using 300+ OSINT data sources
[Link]
95. Shodan - Search engine for Internet connected devices [Link]
96. Maltego - Link analysis and data mining for gathering information [Link]
97. SpiderFoot - OSINT automation tool gathering threat intelligence data [Link]
98. Metagoofil - Extract metadata of public documents from a target website
[Link]
99. TheHarvester - Gather emails, names, URLs from different public sources
[Link]
100. Creepy - Geolocation OSINT tool to extract target location information from social media profiles
[Link]
100 Free Security Tools
For ethical hackers and forensic investigators
Here are those same 100 resources, grouped by function.
Digital Forensics Frameworks:
1. Autopsy - Open source digital forensics platform to analyze hard drives and smart phones
[Link]
10. Forensics (DFF) - Digital forensics framework, an open source platform for investigations
[Link]
22. CAINE - Italian GNU/Linux live distribution with many forensics tools
[Link]
26. Autopsy Browser - GUI interface for autopsy digital forensics platform
[Link]
27. Kali Linux - Penetration testing Linux distribution with many useful security tools
[Link]
28. DEFT - Linux distribution configured specifically for computer forensics
[Link]
29. Volatility Framework - Advanced memory forensics framework with plugins and APIs
[Link]
39. SIFT (SANS) - Ubuntu-based distribution for forensic analysis
[Link]
41. CAINE Live - Self-contained bootable forensic environment
[Link]
59. SANS SIFT - Ubuntu-derived distro for digital forensic analysis
[Link]
68. Rekall - Advanced forensic memory analysis framework powered by Python
[Link]
Disk Forensics:
2. EnCase - Commercial computer forensics software for e-discovery and investigations by OpenText
[Link]
3. AccessData (FTK) - Forensic toolkit computer investigation software by AccessData
[Link]
4. X-Ways Forensics - Integrated computer forensics software by X-Ways Software Technology
[Link]
5. Sleuth Kit - Open source digital forensics tools for analyzing disk images and file systems
[Link]
30. PyFlag - Legacy Australian forensic and log analysis GUI platform
[Link]
32. TSK (The Sleuth Kit) - File system and disk analysis tools originally focussed on NTFS
[Link]
42. XRY (XAMN) - Commercial mobile forensic software to analyze phones [Link]
43. BlackLight - Powerful Windows-based forensics analysis platform
[Link]
44. WinHex - Hex editor, particularly helpful for low-level analyzing raw data
[Link]
45. Access FTK Imager - Disk and volume imaging software from AccessData
[Link]
46. DC3DD - Improved version of dd for forensics, handles errors better
[Link]
47. Raptor - Validation tool to verify integrity of forensic copies
[Link]
48. EnCase Imager - Disk imaging tool from Guidance Software
[Link]
49. Guymager - Open source disk cloning and imaging tool for Linux [Link]
100 Free Security Tools
For ethical hackers and forensic investigators
Memory Forensics:
6. Volatility - Memory forensics framework to analyze volatile memory dumps and artifacts
[Link]
29. Volatility Framework - Advanced memory forensics framework with plugins and APIs
[Link]
60. Live View - Volatile memory analysis tool for Windows systems [Link]
68. Rekall - Advanced forensic memory analysis framework powered by Python [Link]
[Link]/
75. VolDiff - Compares memory images and highlights differences for analysis
[Link]
87. Memoryze - Memory acquisition and analysis tool for Windows systems
[Link]
Carving Tools:
16. Bulk Extractor - Scans disk images and extract interesting bits of data
[Link]
18. Scalpel - File carver which recovers files based on headers and footers
[Link]
50. Scalpel - File carver recovering files based on header/footer signatures
[Link]
51. Extundelete - Used to recover deleted files from mountable images [Link]
52. Xplico - Network forensics tool that rebuilds sessions from traffic [Link]
53. Foremost - File carving utility to recover files using header/footer definitions
[Link]
55. Autopsy Tools - Plugins and tools used alongside Autopsy forensics GUI
[Link]
57. Dislocker - Decrypts Bitlocker encrypted volumes with mounted filesystem
[Link]
58. Bulk Extractor - Extract forensically interesting information from disk images
[Link]
77. hfind - Carves unallocated space and extracts hidden/deleted data into files
[Link]
Network Monitoring:
7. Wireshark - Network protocol analyzer useful for network forensics and traffic analysis
[Link]
14. NetworkMiner - Open source network forensic analyzer useful for investigating traffic
[Link]
34. Snort - Open source intrusion detection and network monitoring system [Link]
35. Tcpdump - Capture and analyze network traffic on Unix-like systems [Link]
36. Ngrep - Search within network traffic payloads like grep for text streams [Link]
38. Wireshark - Network traffic analyzer useful for network forensics [Link]
54. Hunchback - High speed packet capture and transmission tool [Link]
73. AIL - Network and host monitoring system for identification of intrusions [Link]
management/products-services/[Link]
100 Free Security Tools
For ethical hackers and forensic investigators
Windows Artifact Analysis:
15. RegRipper - Tool to parse Windows registry files and dig for useful data
[Link]
25. Fibratus - Tool to explore and trace Windows kernel activity and data
[Link]
61. LRR - Tool for viewing Windows artifacts including LNK files
[Link]
62. NTFS-3G - Open source cross-platform NTFS driver with write support
[Link]
63. WindowsSCOPE - Registry analysis tool for dumped SYSTEM/SAM/SECURITY hives
[Link]
65. Amcache Parser - Recovers data from Windows 10 [Link] artifact file
[Link]
66. The Hive - Web interface offering querying capabilities for hive files [Link]
74. Rifiuti2 - Analyzes Windows Recycle Bin INFO2 files and recovers filenames
[Link]
76. WinAudit - Scans Windows systems and reports changes from baseline [Link]
83. USBDeview - Handy Windows tool listing all USB devices ever connected
[Link]
85. DC3-MWCP - Collection of tools for forensic enterprise analysis from DC3 [Link]
catalog/
88. EVTExtract - Automated parsing modules for Windows event log records
[Link]
Hex Editors:
19. HxD - Hex editor useful for analyzing raw disk and memory dumps [Link]
44. WinHex - Hex editor, particularly helpful for low-level analyzing raw data [Link]
[Link]/winhex/
Data Extraction Tools:
8. Cellebrite UFED - Commercial mobile forensic software to extract data from phones and tablets
[Link]
9. Email Collector - Tool to collect and analyze email data during investigations
[Link]
11. Magnet AXIOM - Commercial digital investigations platform from Magnet Forensics
[Link]
12. Oxygen Detective - Cloud extraction tool for investigations involving cloud services [Link]
[Link]/en/oxygen-detective
13. OSForensics - Specialized forensics tools for Microsoft systems from PassMark
[Link]
23. Axiom Cyber - Commercial digital forensics and incident response platform
[Link]
24. Belkasoft Evidence - Commercial all-in-one forensics solution for Windows, mobile etc
[Link]
31. Plaso (log2timeline) - Extract timestamps from various logs and aggregate timeline
[Link]
33. Redline - Host investigations and malware analysis tool by FireEye
[Link]
37. dcfldd - Disk cloning and forensics tool, version of dd with hashing [Link]
100 Free Security Tools
For ethical hackers and forensic investigators
Data Extraction Tools (continued):
40. Paladin - USB image mounted as virtual drive with write-protection
[Link]
56. OSForensics Imager - Hardware write block tool for connecting devices
[Link]
64. Volafax - Forensic system suited for investigations over remote areas
[Link]
67. GRR Rapid Response - Incident response framework focused on remote live forensics
[Link]
69. DFF - Open source digital forensics framework and platform written in Python
[Link]
70. SSDeep - Fuzzy hashing tool used for malware clustering and piecewise comparisons [Link]
[Link]/ssdeep/[Link]
71. KAPE - Target acquisition tool focused on enterprise lines of business
[Link]
79. Checkm8 - Jailbreaking tool extracting data from passcode locked iOS devices [Link]
80. Olefile - Python package for parsing OLE and Office documents [Link]
84. Autopsy - iPhone - Autopsy module adds iOS analysis functionality
[Link]
Data Recovery Tools:
20. TestDisk - Data recovery tool, useful when file systems get corrupted
[Link]
21. PhotoRec - Recovery tool specifically focused on photos and media files
[Link]
Specialized Tools:
17. Ghiro - Web site screenshots and analysis for forensic investigations [Link]
81. Pyew - Python tool for malware analysis static and dynamic [Link]
82. E01 Examiner - Software utility for mounting EnCase evidence file formats [Link]
86. X-Ways Imager - Disc imaging tool to create forensic images, integrated into X-Ways Forensics
[Link]
89. Speedit - Detection and analysis of spyware, keyloggers, trojans etc [Link]
sdk
90. SniffPass - Sniffs passwords and other sensitive information from a network
[Link]
OSINT Tools:
91. Nmap - Network scanning and host discovery tool helpful for reconnaissance [Link]
92. OSINT Framework - Gathering publicly available online data regarding targets
[Link]
93. Recon-ng - Web based open source reconnaissance framework [Link]
ng
94. OSINT-SPY - Performs extensive reconnaissance using 300+ OSINT data sources
[Link]
95. Shodan - Search engine for Internet connected devices [Link]
96. Maltego - Link analysis and data mining for gathering information [Link]
97. SpiderFoot - OSINT automation tool gathering threat intelligence data [Link]
98. Metagoofil - Extract metadata of public documents from a target website
[Link]
100 Free Security Tools
For ethical hackers and forensic investigators
OSINT Tools (continued):
91. Nmap - Network scanning and host discovery tool helpful for reconnaissance [Link]
92. OSINT Framework - Gathering publicly available online data regarding targets
[Link]
93. Recon-ng - Web based open source reconnaissance framework [Link]
ng
94. OSINT-SPY - Performs extensive reconnaissance using 300+ OSINT data sources
[Link]
95. Shodan - Search engine for Internet connected devices [Link]
96. Maltego - Link analysis and data mining for gathering information [Link]
97. SpiderFoot - OSINT automation tool gathering threat intelligence data [Link]
98. Metagoofil - Extract metadata of public documents from a target website
[Link]
99. TheHarvester - Gather emails, names, URLs from different public sources
[Link]
100. Creepy - Geolocation OSINT tool to extract target location information from social media profiles
[Link]
FOLLOW ME ON:
(click icon below)
INSIDE CLOUD