Your use of the packages on this site means you understand they are not supported or guaranteed in any way. Due to the nature of a public repository and unreliability due to distribution rights, these packages should not be used as is for organizational purposes either. Learn more.
Search for "tag:forensic" Returned 51 Package s
Displaying Results 1 - 30 of 51
- Passing
- Failing
- Pending
- Unknown / Exempted
-
4,182 Downloads
Fast, multi-threaded file hashing utility
- By:
- EricRZimmerman
>
-
4,997 Downloads
X-Ways Forensics Installation Manager
- By:
- EricRZimmerman
>
-
3,277 Downloads
Windows Volume Shadow Copy mounting tool
-
4,520 Downloads
TimeApp displays the current and UTC times with millisecond precision
- By:
- EricRZimmerman
>
-
8,156 Downloads
ShellBags Explorer allows for visually viewing and interacting with shell bags found in usrclass.dat and ntuser.dat Registry hives
-
3,862 Downloads
GUI SDB parser
- By:
- EricRZimmerman
>
-
10,779 Downloads
Registry Explorer is a Windows Registry analysis tool with a ton of functionality not found anywhere else
- By:
- EricRZimmerman
>
-
2,524 Downloads
Windows Recycle Bin parser
- By:
- EricRZimmerman
>
-
6,567 Downloads
Windows prefetch parser
- By:
- EricRZimmerman
>
-
7,164 Downloads
lnk (Windows shortcut) parser
- By:
- EricRZimmerman
>
-
5,728 Downloads
GUI jumplist parser with Windows 10 support
- By:
- EricRZimmerman
>
-
5,515 Downloads
geolocate ip addresses in IIS logs
- By:
- EricRZimmerman
>
-
8,186 Downloads
AppCompatCache aka shimcache parser
>
-
7,302 Downloads
Amcache.hve parser
- By:
- EricRZimmerman
>
-
71,048 Downloads
The Volatility Framework is a completely open collection of tools, implemented in Python under the GNU General Public License, for the ext... Keep Reading
- By:
- SebastianK
- Tags:
- ram
- memory
- analysis
- investigation
- forensic
>
-
Tool to find metadata and hidden information in documents
- By:
- dgalbraith
>
-
68 Downloads
Tableau Forensic Imager (TIM) is Tableau's free forensic imaging software application.
- Tags:
- tableau-imager
- forensics
- dfir
>
-
65 Downloads
bulk_extractor is a high-performance digital forensics exploitation tool.
>
-
34 Downloads
Emulates the Sysinternals Autoruns tool, but for DFIR purposes e.g. multi user processing
- Tags:
- autorunner
- autoruns
- forensics
- dfir
>
-
70 Downloads
Fast suspicious file finder for incident response.
>
-
137 Downloads
A forensic utility for converting data found on desktop and mobile devices into human-readable timestamps.
-
65 Downloads
Parser for $UsnJrnl on NTFS
>
-
72 Downloads
Extract $MFT record info and log it to a csv file.
-
94 Downloads
Hibernation Recon extracts forensic data from Windows hibernation files.
- Tags:
- hibernation-recon
- forensics
- dfir
>
-
165 Downloads
Volatility is the world's most widely used framework for extracting digital artifacts from volatile memory (RAM) samples.
- Tags:
- volatility3
- memory
- ram
- forensics
- dfir
>
-
66 Downloads
Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
-
106 Downloads
Android Logs Events And Protobuf Parser
>
-
293 Downloads
Arsenal Image Mounter mounts the contents of disk images as complete disks in Microsoft Windows.
- Tags:
- arsenalimagemounter
- forensics
- dfir
>
-
112 Downloads
Web browser forensics for Google Chrome/Chromium
-
108 Downloads
Web browser forensics for Google Chrome/Chromium

Join the Chocolatey Team on our regular monthly stream where we discuss all things Community, what we do, how you can get involved and answer your Chocolatey questions.

Join the Chocolatey Team on our regular monthly stream where we put a spotlight on the most recent Chocolatey product releases. You'll have a chance to have your questions answered in a live Ask Me Anything format.

Livestream from
Thursday, 06 October 2022
We recently released our largest update to Chocolatey Central Management so far. Join Gary and Steph to find out more about Chocolatey Central Management and the new features and fixes we've added to this release.
Watch On-Demand
Webinar Replay from
Wednesday, 30 March 2022
At Chocolatey Software we strive for simple, and teaching others. Let us teach you just how simple it could be to keep your 3rd party applications updated across your devices, all with Intune!
Watch On-Demand
Livestream from
Thursday, 9 June 2022
Join James and Josh to show you how you can get the Chocolatey For Business recommended infrastructure and workflow, created, in Azure, in around 20 minutes.
Watch On-Demand
Livestream from
Thursday, 04 August 2022
Join Paul and Gary to hear more about the plans for the Chocolatey CLI in the not so distant future. We'll talk about some cool new features, long term asks from Customers and Community and how you can get involved!
Watch On-Demand
Livestreams from
October 2022
For Hacktoberfest, Chocolatey ran a livestream every Tuesday! Re-watch Cory, James, Gary, and Rain as they share knowledge on how to contribute to open-source projects such as Chocolatey CLI.
Watch On-Demand
Livestream from
Thursday, 03 November 2022
Join Paul and Gary for this months Chocolatey product livestream where we look at the latest release of Chocolatey 1.2.0, Chocolatey Licensed Extension 5.0.0 and shine a spotlight on the new hook scripts functionality. This opens up so many possibilities for Chocolatey CLI users!
Watch On-Demand
Livestream from
Tuesday, 29 November 2022
Join Josh as he adds the ability to manage Chocolatey GUI config and features with the Chocolatey Ansible Collection.
Watch On-Demand
Webinar from
Tuesday, 13 December 2022
Join Gary, Paul, and Maurice as they introduce and demonstrate how to use Chocolatey! Questions will be answered live in an Ask Me Anything format.
Watch On-Demand