Fox is a versatile commandline tool, built to support the examination process of file-based forensic evidence. It provides a wide spectrum of forensic capabilities in a cross-platform standalone binary.
Via Go
Via Homebrew
Example Usage
Specialized tools for basic forensic tasks.
Dump Active Directory password hashes.
Hash files using many algorithms.
Reverse lookup hash algorithms.
Extract the bootkey from the system hive.
Check resources for malevolence.
Lookup Windows event log messages.
Calculate entropy of files and paths.
Carve Unicode and ASCII strings from files.
Remove ANSI color escape sequences.
Unique wordlist from different sources.
A corpus of various file formats for testing.
About artifacts, compression and more...
The Forensic Artifacts Collecting Toolkit.
Mount disk images for forensic processing.
Find forensic artifacts on the system.
Log forensic artifacts as ECS.
Cutting-edge tools not meant for production use.
Fast event record analyzer.
Fox Forensics is dedicated to advancing digital forensics through open-source tooling. Based in Germany, we build reliable utilities for forensic examiners and incident responders.
Our tools are designed with forensic integrity in mind: non-destructive analysis, chain of custody preservation, and reproducible results.