▲

DFIR Collection Toolkit

Digital Forensic Incident Response Artifact Collection Toolkit

Company: Personal Project

Overview

When responding to a potential breach, speed and consistency are critical. The Digital Forensic Incident Response & Artifact Collection Suite is a unified, open-source live-response toolkit designed to perform automated triage across Linux, Windows, and macOS systems.

By querying native operating system interfaces and low-level kernel metadata, the toolkit gathers volatile and non-volatile evidence, exports structured CSV deliverables, generates SHA-256 integrity hashes, and builds an offline HTML analysis dashboard for rapid threat identification.

Key Capabilities & Coverage

  • Multi-OS Parity: Standardized collection logic for Linux (.sh), Windows (.ps1), and macOS (.sh).

  • Volatile & Non-Volatile Inspection: Captures running process trees, network sockets, active persistence mechanisms, user accounts, and execution hooks.

  • Execution Hook Detection: Specifically audits userland rootkits and debugging hijacking—such as /etc/ld.so.preload on Linux and Image File Execution Options (IFEO) on Windows.

  • Automated Risk Scoring: Built-in threat detection rules flag high-risk process execution paths (/tmp, AppData\Local\Temp), reverse shells, and unauthorized privilege escalation vectors.

  • Chain of Custody: Calculates SHA-256 cryptographic hashes for every output CSV and packages evidence into a secure, timestamped archive (.tar.gz / .zip).

  • Artifact Search Function: Allows for a quick search of all artifacts collected opening the cooresponding artifacts searched.
Artifact search

Artifact Mapping Architecture

DomainLinux ImplementationWindows ImplementationmacOS Implementation
Processes/proc, ps auxWin32_Process, Get-Processlaunchctl, ps
User Profiles/etc/passwd, /home/*Win32_UserProfile, C:\Users/Users/*
Privileges/etc/sudoers, /etc/groupLocal Administrators Groupadmin group membership
Execution Hooks/etc/ld.so.preloadRegistry: IFEO DebuggersDYLD_INSERT_LIBRARIES
Persistencecrontab, systemd timersGet-ScheduledTask, ServicesLaunchDaemons, LaunchAgents

Getting Started

The full suite is available on GitHub. You can execute live collection in minutes:

# Linux / macOS
    sudo ./Linux/IR_DFIR_Collection_Toolkit_v1_1.sh
# Windows (Elevated PowerShell)
    .\Windows\IR_DFIR_Collection_Toolkit_v1_2.ps1

Command-Line Switches & Operational Flags

The toolkit operates in Trial mode by default to allow safe dry-runs and validation without modifying host state. You can pass explicit flags to trigger active triage actions, isolate compromised hosts, attach incident metadata, or request memory dumps.

sudo ./IR_DFIR_Collection_Toolkit_v1_1.sh [options]

Available Options

Option / FlagTypeDescription
--liveSwitchExecutes collection actions for real. Without this flag, the script runs in safe Trial mode (dry-run).
--disable-networkingSwitchImmediately isolates the host by disabling active network interfaces to contain lateral movement or C2 traffic.
--collect-memorySwitchFlags a request to capture a full RAM image from volatile memory alongside standard forensic artifacts. (future option)
--incident-id <ID>ArgumentAttaches a unique Incident Tracking ID (e.g., INC-2026-8801) to the report header and evidence metadata.
--case-number <NUM>ArgumentAssociates the collection run with an official forensic case number (e.g., CASE-0412).
--analyst <NAME>ArgumentTags the generated dashboard, evidence archive, and log files with the assigned responder's name or ID.
--log-format <json|csv>ArgumentSpecifies the output format for the execution transcript log (IR_Execution_Log). Default is json.

Usage Examples

1. Safe Trial Run (Dry-Run / Non-Destructive)

Runs artifact checks in trial mode without taking active isolation steps or live system modifications:

sudo ./IR_DFIR_Collection_Toolkit_v1_1.sh --analyst "T. Leadley" --log-format json

2. Standard Live Incident Triage

Executes live collection, tags the case details, and generates structured CSV logs:

sudo ./IR_DFIR_Collection_Toolkit_v1_1.sh --live --incident-id INC-8801 --case-number C-2026-09 --analyst "T. Leadley" 

3. Emergency Containment & Memory Capture

Isolates a compromised host from the network immediately while executing a live triage and flagging volatile memory acquisition (future option):

sudo ./IR_DFIR_Collection_Toolkit_v1_1.sh --live --disable-networking --collect-memory --incident-id INC-9904 --analyst "T. Leadley"

View Project on GitHub →