↓ Skip to main content

Tools

·4 mins·
Table of Contents

Every incident response engagement starts with the same problem: getting the right data off a system, fast, and turning it into something you can actually read. On this page we share the tools we and our clients use for that: small, focused utilities that collect digital evidence and parse the artifacts it contains.

All of them are free and open, and most are command-line tools that fit into scripted, large-scale collection just as well as into a single live-response session.

Triage collection
#

Triage is a small set of data that is usually enough to analyse a system, and in most cases it is a reasonable alternative to a full disk image. Standard solutions are not a fit for every environment though. Old operating system versions, limited access windows or restricted tooling all get in the way. In those cases the collectors below may be the working solution.

WindowsLinuxmacOSRust
A fast and efficient triage collection tool written in Rust. Aralez gathers the artifacts an investigation usually starts with, such as event logs, registry hives, prefetch files, user activity and memory-related data, and it runs on Windows, Linux and macOS. Built for speed and low system impact, it suits both live response and scripted collection workflows.
WindowsPython
A Python-based forensic triage tool that collects and parses critical artifacts from Windows disk images, including event logs, registry hives and prefetch files, without imaging the entire hard drive. It works on disk images rather than live systems and integrates with tools like Kuiper for visualisation and Rhaegal for detection.
LinuxRust
An artifact collection tool for *nix based systems, written in Rust. Fennec is driven by a configuration file that describes how artifacts should be collected, which makes it easy to adapt to unusual or heavily customised environments.

Parsers
#

Collection is only half of the work. The parsers below turn individual Windows artifacts into structured output, usually JSON or CSV, that can be fed into a timeline, a detection pipeline or plain grep.

WindowsRust
A high-performance parser for Windows Event Log (.evtx) files. Supports JSON output and batch processing, which makes it a good fit for automation, timeline creation and event correlation.
WindowsRust
A fast, standalone parser for NTFS Master File Table entries. Extracts detailed file metadata including timestamps, file paths and change history, which form the backbone of deep-dive analysis and timeline building.
WindowsRust
A robust implementation for parsing Windows LNK (shortcut) files. These artifacts reveal file access history, user behaviour and potential lateral movement.
WindowsRust
Parses the $Secure:$SDS stream of the NTFS file system, exposing historical security descriptors. Enables the analysis of permission changes and access control lists.
WindowsRust
Extracts metadata from $I files in the Windows Recycle Bin, such as original path, deletion time and the user behind it, which is useful for recovering information about deleted files.
WindowsRust
A parser for CryptnetURLCache metadata files used by the Windows certutil tool. Useful for uncovering certificate-related operations and remote resource access.
WindowsRust
Analyses Notepad’s TabState artifact, revealing unsaved documents and recent file interactions. Supports user activity reconstruction in data leak and insider threat cases.
WindowsPython
Parses and analyses Windows Amcache.hve registry hives to identify evidence of execution and suspicious executables, with optional VirusTotal and OpenTIP lookups for threat intelligence context.
WindowsPython
Parses UserAssist artifacts from Windows registry hives. It walks a directory, finds NTUSER.DAT files, decodes UserAssist entries and reports the user, the executed application, run count, last run time, focus count and focus time.
WindowsPython
A DFIR automation tool that parses the various Windows forensic artifacts collected during incident response and post-incident investigations in one pass.

Suggest a tool
#

Do you maintain or use a collector or parser that earned its place in your investigations? Tell us about it at info @ purpleshift.io and we will look at adding it to this page.

Disclaimer: the tools listed here are developed and maintained by their respective authors, not by Purpleshift. We share them because we find them useful in practice. Review and test any of them before running it in a production or evidentiary context.