Open Source ยท Free ยท Windows 10/11

Digital Forensics
Investigation Suite

A professional-grade forensics toolkit for investigators, security analysts, and researchers. Analyze memory dumps, network captures, event logs, and detect malware โ€” all from one unified interface.

โœ“ No account required โœ“ No telemetry โœ“ MIT Licensed
ForensicToolkit โ€” Analysis Console

[INFO] Loading case: CASE-2024-0042

[INFO] Memory image: dump.raw (4096 MB)

[INFO] Processes found: 47

[ALERT] Suspicious process: mimikatz.exe (PID 3842)

[INFO] Network connections: 312 packets

[ALERT] C2 traffic detected โ†’ 185.220.101.x

[INFO] YARA scan: 3 threats / 1,204 files

[INFO] Generating PDF report... Done

โ–ˆ

9+Analysis Modules
3Report Formats
AIPowered Insights
100%Open Source

Everything you need for a complete investigation

โšก

All-in-One Interface

Every forensic module in a single unified Qt6 application. No switching between tools.

๐Ÿค–

AI-Powered Analysis

Connect GPT-4, Claude, or local Ollama models to automatically analyze evidence and generate investigation summaries.

๐Ÿ“„

Court-Ready Reports

Export findings as professional PDF, HTML, or JSON reports with chain-of-custody, case metadata, and executive summaries.

๐Ÿ”’

Hash Verification

MD5, SHA-1, SHA-256 hashing with OpenSSL. Verify evidence integrity throughout the investigation lifecycle.

๐Ÿ›ก

YARA Detection

Load custom YARA rule sets for malware detection. Built-in heuristics catch packed PEs, shellcode, and extension mismatches.

๐ŸŒ

Deep PCAP Analysis

Native PCAP parser reconstructs TCP streams, DNS queries, HTTP sessions, and flags suspicious C2 traffic patterns.

Nine specialized investigation modules

๐Ÿ—‚

File System Analyzer

Recursive directory scanning with MIME detection, hidden file discovery, duplicate detection by hash, and full metadata extraction.

Disk Forensics
๐Ÿ”’

File Integrity Monitor

Create cryptographic baselines and detect modified, added, or deleted files. Track tampered evidence across time.

Integrity
๐Ÿง 

Memory Analyzer

Parse raw memory dumps to extract running processes, loaded DLLs, network connections, and ASCII/Unicode strings.

Memory Forensics
๐ŸŒ

Network Forensics

Native PCAP parser with Ethernet/IPv4/TCP/UDP/DNS/HTTP dissection. Reconstructs sessions and identifies suspicious hosts.

Network
๐Ÿ“‹

Event Log Parser

Parse Windows EVTX exports for failed logins, USB insertions, process executions, and security audit events.

Windows Forensics
๐Ÿฆ 

Malware Detector

YARA-based scanning engine with built-in heuristics for shellcode, packed PEs, and extension mismatches.

Malware Analysis
๐Ÿค–

AI Assistant

Connects to OpenAI, Anthropic, OpenRouter, or local Ollama. Generates structured investigation reports mapped to MITRE ATT&CK.

AI / LLM
๐Ÿ“Š

Report Generator

Export complete case findings as PDF (printer-quality), HTML, or machine-readable JSON with full case metadata.

Reporting
๐Ÿ“‚

Case Manager

SQLite-backed case database. Track investigators, evidence chain-of-custody, case status, and all analysis results per case.

Case Management

Runs on any modern Windows machine

Minimum

  • Windows 10 64-bit (1909+)
  • 4 GB RAM
  • 500 MB disk space
  • 1280ร—720 display

Recommended

  • Windows 11 64-bit
  • 16 GB RAM
  • SSD with 10 GB free
  • 1920ร—1080 display

Dependencies

  • Included in installer
  • Qt 6.11 runtime (bundled)
  • OpenSSL 4.x (bundled)
  • No .NET or Java required

Ready to investigate?

Free and open source. No registration. No limits.

Windows 10/11 ยท 64-bit ยท Free forever