A curated list of awesome free forensic analysis tools, resources, and learning materials for digital investigators.
Awesome Forensics is a curated GitHub repository listing free and open-source tools, frameworks, and resources for digital forensics and incident response. It helps investigators find software for evidence collection, analysis, and timeline reconstruction across operating systems and devices. The project organizes hundreds of specialized tools into categories like memory forensics, disk imaging, and artifact parsing.
Digital forensics professionals, incident responders, cybersecurity students, and CTF participants who need a reference for forensic tools and learning materials. It's also valuable for security researchers building investigation workflows.
It saves time by aggregating and categorizing the scattered landscape of forensic tools into a single, community-vetted list. Unlike commercial platforms, it focuses exclusively on free and open-source options, promoting accessibility and transparency in digital investigations.
⭐️ A curated list of awesome forensic analysis tools and resources
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Organizes hundreds of forensic tools into 20+ specific categories like memory forensics and disk imaging, as detailed in the README's table of contents, saving time in tool discovery.
Covers tools and learning materials for Windows, Linux, macOS, mobile, and cloud environments, evidenced by dedicated sections like OS X Forensics and Mobile Forensics.
Actively maintained with contributions from the DFIR community, ensuring the list stays current with new tools and challenges, as shown by the CI badge and contribution guidelines.
Includes CTF challenges, blogs, books, and labs under Learn Forensics and Resources, providing pathways to build forensic skills beyond just tool listings.
The list only catalogs tools without ratings, reviews, or guidance on which are best for specific tasks, leaving selection entirely to the user's research.
Relies on community contributions, so some tools may be deprecated or unmaintained without clear indicators, requiring users to verify tool status independently.
With over 100 tools and no beginner-friendly filtering or tutorials, it can be difficult for newcomers to navigate without additional learning resources.