GitPedia

ArtifactParsers

A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts

From Digital-Forensics-Discord-Server·Updated May 15, 2026·View on GitHub·

A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts. The project is distributed under the MIT License license, first published in 2023. Key topics include: computerforensics, dfir, dfir-tools, digitalforensics.

ArtifactParsers

A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts.

What makes this different from any other list of DFIR tools?

Ideally, the community will maintain this as tools come and go from relevance. If a tool is listed below, the community is vouching for it that it still works and is an excellent option to solve whatever problem you may be facing with a particular artifact.

Commercial Tool Disclaimer

It's not that commercial tools aren't welcome in this list, but the table would become pretty bloated when you have 5+ tools duplicated in many cells. At the very minimum, this project aims to highlight single-purpose tools made by the DFIR community members to allow for greater visibility at the options (often at no cost) for those looking to solve problems in their everyday investigations.

Much love for the commercial vendors, their efforts, and their contributions to the community, but it would be ideal for anyone looking to learn more about the capabilities of a commercial tool to reach out to the vendor themselves or visit their official website for more information.

Analyzers vs. Parsers

In the instance of Windows Event Logs, the Windows Registry, and possibly other artifacts, there is a distinct difference between a tool that analyzes an artifact and parses the artifact. Generally speaking, an analysis tool would do something similar to running YARA or SIGMA rules against a set of artifacts and provide meaningful output based on the rulesets used. A parser would provide raw output without any predetermined rulesets or logic applied to the set of artifacts, leaving the analysis and interpretation to the end examiner.

This is an important distinction to make with this project because, in the example of Windows Event Logs, it would be troublesome to lead an examiner looking for a tool to parse Windows Event Logs to think that a tool like Chainsaw, Hayabusa, or Zircolite will parse event logs when in reality they analyze the event logs using rulesets and logic created by threat researchers. Those tools do not PARSE the event logs like EvtxECmd, etc.

Contributing

Please contribute to this list if any artifacts and their corresponding tools still need to be included!

Windows

DFIR ArtifactCLI Tool(s)GUI Tool(s)
$I30go-ntfs<br>Index2Csv<br>IndexCarver<br>MFTECmd
$Jdfir_ntfs<br>ExtractUsnJrnl<br>go-ntfs<br>MFTECmdNTFS Log Tracker
$LogFiledfir_ntfs<br>go-ntfs<br>LogFileParser<br>RcrdCarverNTFS Log Tracker
$MFTdfir_ntfs<br>Mft2Csv<br>MftCarver<br>MFTECmd<br>MftRcrdMFT_Browser<br>MFTExplorer<br>NTFS Log Tracker
$SDSMFTECmd<br>Secure2Csv
AmcacheAmcacheParserRegistry Explorer
AppCompatCache (ShimCache)AppCompatCacheParserRegistry Explorer
AppCompatCache PCA (Windows 11 only)PCAParser
Browsing HistoryBrowsingHistoryView<br>Hindsight - Chromium only<br>SQLECmd - SQLite onlyBrowsingHistoryView<br>Browser History Viewer
CSV FilesModern CSV<br>Timeline Explorer
Email (MBOX)mbox-web-viewermboxviewer
Email (OST/PST)XstExporterXstReader
ESE Databases (General)WindowsEDB-to-CSVESEDatabaseView<br>WinEDB
ETL FilesETLParser
Event Logs (.evtx) - AnalyzersChainsaw<br>EvtxHussar<br>Hayabusa<br>Zircolite
Event Logs (.evtx) - ParsersEvents-Ripper<br>EvtxECmdEvent Log Explorer<br>Event Log Observer<br>Evtx_Log_Browser<br>FullEventLogView<br>LogViewPlus
Google DrivegMetaDataParsegMetaDataParse
IIS LogsIISGeoLocateLogViewPlus
Image MountingArsenal Image MounterArsenal Image Mounter
IP Address GeoLocationAbeebus
JumpListsJLECmdJumplist-Browser<br>JumpList Explorer
LevelDBLevelDBDumperLevelDB Recon
LNK FilesLECmdJumplist-Browser
MalwareBytes LogsMBAMServiceLogParser.ps1
NetWire LogsNetWireLogDecoder
OneDriveOneDrive .ODL Parser<br>OneDriveExplorerOneDriveExplorer
PrefetchPECmdPrefetch-Browser<br>WinPrefetchView
RAM (Memory)Memory-Baseliner<br>VolatilityMemProcFS<br>Volatility Workbench
RDP Bitmap CacheBMC-Tools
Recycle BinRBCmd
RecentFileCacheRecentFileCacheParser
Registry - Analyzersreg_hunter
Registry - Comparison ToolsRegistryChangesView<br>RegShot-Advanced
Registry - Parsersjarp<br>RECmd<br>Registry Recon<br>RegRipper<br>yarpRegistry Explorer
ShellbagsSBECmdShellbags Explorer
Shim DatabasesSDB Explorer
SQLite DatabasesSQLECmdDB Browser for SQLite<br>FQLite<br>Navicat for SQLite<br>SQLiteStudio
SRUM Database (ESE)SrumECmd<br>srum-dump
SUM Database (ESE)SumECmd
Symantec AV LogsSEParserSEParser
ThumbcacheThumbcache Viewer (CMD)Thumbcache Viewer
Volume Shadow CopiesVSCMountShadowExplorer
Windows TimelineWxTCmd<br>Windows Timeline PowerShell ScriptsClippy.exe<br>WindowsTimeline.exe
WBEM (WMI)flare-wmi<br>PyWMIPersistenceFinder<br>WMIParserStr<br>WMI-ParserWMI-Explorer
Windows Defender LogsDHParser
Windows Search Index DatabaseSIDR<br>WinEDBWinSearchDBAnalyzer<br>WinEDB

Android

DFIR ArtifactCLI Tool(s)GUI Tools(s)
Android ArtifactsALEAPP<br>AndrillerALEAPP<br>Andriller<br>Avilla Forensics
SQLite DatabasesSQLECmdDB Browser for SQLite<br>FQLite

iOS

DFIR ArtifactCLI Tool(s)GUI Tools(s)
iOS ArtifactsiLEAPPArtEx<br>iLEAPP
PList FilesMushy<br>plist Editor Pro
SQLite DatabasesSQLECmdDB Browser for SQLite<br>FQLite
Advanced logical backup & acquisitionUFADE

macOS

DFIR ArtifactCLI Tool(s)GUI Tools(s)
macOS Artifactsmac_apt

Contributors

Showing top 4 contributors by commit count.

View all contributors on GitHub →

This article is auto-generated from Digital-Forensics-Discord-Server/ArtifactParsers via the GitHub API.Last fetched: 6/28/2026