f4analyse: Open-Source Forensic Analysis Tool
An open-source, cross-platform forensic analysis tool for analyzing digital evidence, including disk images, memory dumps, logs, and network captures.
What is F4analyse?
f4analyse is an open-source digital forensics and incident response tool for analyzing disk images, memory dumps, network traffic captures, log files, and other digital evidence. It runs on Windows, Linux, and macOS.
Key features of f4analyse include:
- Timeline analysis - Extract metadata and generate detailed timelines to reconstruct user activities
- File carving - Recover deleted files from unallocated disk space using file signature analysis
- Data visualization - View analysis results through timeline, graph, and tree visualizations
- Reporting - Generate custom reports containing analysis details and findings
- File system analysis - Conduct in-depth analysis of multiple file systems including NTFS, FAT, HFS+, Ext, and more
- Memory analysis - Dump and analyze memory from Windows, Linux, and macOS systems
- Multi-evidence correlation - Correlate findings across disk images, network captures, memory dumps, etc.
- Customizable interface - Tailor workspace layouts and color schemes for analysis tasks
- Scripting - Automate workflows through Python scripts for batch processing evidence
f4analyse is free and open-source software licensed under GPLv2. It can expedite investigations and provide deep insight into cases involving digital evidence.