GetData Forensic Imager
Windows based program that will acquire, convert, or verify a forensic image in one of the following common forensic file formats.
- from
- Incident Response
- added
- 2026-10-10
- likes
- 0
similar
-
-
AccessData FTK Imager accessdata.com
Forensics tool whose main purpose is to preview recoverable data from a disk of any kind. FTK Imager can also acquire live memory and paging file on 32bit and 64bit systems.
-
FastIR Collector github.com
Tool that collects different artifacts on live Windows systems and records the results in csv files. With the analyses of these artifacts, an early compromise can be detected.
-
FastIR Collector Linux github.com
FastIR for Linux collects different artifacts on live Linux and records the results in CSV files.
-
IOC Finder fireeye.com
Free tool from Mandiant for collecting host system data and reporting the presence of Indicators of Compromise (IOCs). Support for Windows only. No longer maintained. Only fully supported up to Windows 7 / Windows Server 2008 R2.
-
OSForensics osforensics.com
Tool to acquire live memory on 32-bit and 64-bit systems. A dump of an individual process’s memory space or physical memory dump can be done.
Incident Response › IR Tools Collection > Disk Image Creation Tools: “Windows based program that will acquire, convert, or verify a forensic image in one of the following common forensic file formats.”