defencia/knowledge/software
Toolset · Licensing · DFIR

Software

An overview of the software covered in the course — imaging, forensics, virtualization, SIEM and documentation tools — with a note on licensing for each.

ToolsetMostly free

Software used in the field

An overview of the tools covered, with licensing. Replacements happen, so this can change.

ToolPurposeLicense
AutopsyForensic framework (Sleuth Kit); ingest modules + plugins.Free / OSS
VMware / VirtualBoxVirtualization. VMware is the author's favourite; VirtualBox is free.~$200 / Free
EmEditorText editor that opens files up to 250 GB — handy for huge logs on Windows.$259 lifetime / $40 yr
SplunkSIEM; quick to install and start analysing logs. Free up to 500 MB/day.Free tier
SOF-ELKSANS (Phil Hagen) ELK appliance; recognises common log formats, but needs Elastic/Kibana/Logstash knowledge to customise.Free
LinuxA multitool in itself — does a lot with few resources.Free
SimpleMind ProMind mapping — don't underestimate it for summarising topics.~$28 lifetime
ScreenpressoImage / video / audio capture for documentation.Free / ~$45
WindowsOS; trial license works 90 days with full functionality.OEM / Volume
FTK ImagerFree imaging tool (AccessData) — AD1, DD, E01. USB media may need a separate write-blocker.Free
dd / dc3dd / dcflddLinux imaging tools; variants add hashing and progress bars.Free / OSS