Digital Forensic
STAGE TOOL PLATFORM PURPOSE WHY WE USE IT
NAME
PREPARATION Nmap Kali Network discovery To identify active devices
Linux&windows and port scanning. and open ports on a
network for forensic or
penetration purposes.
Hashcat Kali Linux Password recovery To recover lost passwords
and cracking. or test system security by
cracking hashes.
John the Kali Linux Password auditing To perform brute-force or
Ripper and recovery. dictionary attacks for
forensic password
recovery or system
auditing.
Wireshark Windows, Linux Network packet To capture and analyze
analysis. network traffic for
evidence of intrusion or
suspicious activity.
EVIDENCE FTK Windows Disk imaging and To create forensic images
ACQUISITION Imager data preview. of drives and preview
evidence without altering
the original data.
ANALYSIS Autopsy Windows, Linux Digital forensic To recover deleted files,
analysis of hard analyze file systems, and
drives and disk investigate user activity.
images.
Volatility Kali Linux Memory forensics To analyze RAM dumps
and analysis. for malware, encryption
keys, or evidence of
unauthorized activity.
Ethical Hacking
Stage Tool Platform Purpose Why We Use It
SET (Social Kali Simulating social To test phishing, email
Engineering engineering spoofing, and other
Toolkit) attacks. social engineering
vectors.
Scanning OpenVAS Kali Vulnerability To identify and report
scanning and security weaknesses in
management. systems.
Exploitation Metasploit Kali Exploitation To test system defenses
framework for by simulating real-world
penetration testing. attacks.
Aircrack-ng Kali Wireless security To crack WEP/WPA
analysis and keys and test Wi-Fi
testing. network security.
John the Kali Password cracking To test the strength of
Ripper and hash testing. passwords in a secure
environment.
Reconnaissanc Nmap Kali & Network scanning To identify open ports,
e Windows and mapping. services, and
vulnerabilities on a
network.
Wireshark Kali & Network protocol To capture and analyze
Windows analysis. network traffic for
identifying suspicious
activities.
Burp Suite Kali & Web application To find vulnerabilities in
Windows security testing. websites, such as SQLi
and XSS.
Burp Suite Kali & Web application To exploit vulnerabilities
Windows security testing. in web applications.
Hashcat Kali & Advanced To crack password
Windows password recovery hashes using GPU
tool. acceleration.
Post- John the Kali Password To extract credentials
Exploitation Ripper cracking and and escalate
hash testing. privileges.
Post- John the Kali Password To extract credentials
Exploitation Ripper cracking and and escalate
hash testing. privileges.
Post- John the Kali Password To extract credentials
Exploitation Ripper cracking and and escalate
hash testing. privileges.
Autopsy Kali & Digital forensic To analyze disk images
Windows investigations. and recover deleted files
during investigations.
Defense/ Wireshark Kali & Network protocol To identify and mitigate
Analysis Windows analysis. suspicious activities in
network traffic.
Autopsy Kali & Digital forensic To analyze disk images
Windows investigations. and recover deleted files
during investigations.
Defense/ Wireshark Kali & Network protocol To identify and mitigate
Analysis Windows analysis. suspicious activities in
network traffic.
Autopsy Kali & Digital forensic To analyze disk images
Windows investigations. and recover deleted files
during investigations.
Stage Tool Platform Purpose Why We Use It
FTK Windows Forensic To analyze and recover
(Forensic investigations and digital evidence from
Toolkit) data recovery. systems.
FTK Windows Forensic To analyze and recover
(Forensic investigations and digital evidence from
Toolkit) data recovery. systems.
FTK Windows Forensic To analyze and recover
(Forensic investigations and digital evidence from
Toolkit) data recovery. systems.
The number Kali Windows
10
11
12
13
14
15
16
17
18
19
20
Main device