
Forensicator
Summary
Forensicator is a free, open-source toolkit for collecting and analyzing system artifacts during live investigations. It produces a searchable HTML report and a structured investigation JSON folder; Windows also creates a case-summary JSON rollup. The collector runs from a cloned repository without an agent or provisioning, but full artifact access requires elevated permissions. It evaluates more than 1,400 community Sigma rules, with coverage varying by operating system, and checks malware hashes and indicators against automatically updated threat-intelligence feeds. Windows collection includes RAM acquisition and network capture converted to PCAP. Optional AI analysis can provide finding-level verdicts and a summary with a risk score, timeline, and attack chain; these AI features are Windows-only and can use local Ollama or listed commercial providers. Collected artifacts can be encrypted, but decryption is available on Windows and Linux, not macOS. Enterprise is self-hosted report-management software for teams, with an authenticated API, webhooks, access controls, activity logging, and configurable retention; its price is not listed.
Who it is for
The free collector suits incident responders and digital forensics teams that need to gather and review system artifacts. Enterprise is presented for security operations centers, response and forensics teams, and MSSPs managing reports across teams.
What is good
- Free and released under the MIT License
- Produces searchable HTML and structured JSON output
- Checks artifacts against Sigma rules and threat feeds
- Enterprise offers API access and webhooks
What to know first
- Full artifact access requires elevated permissions
- AI investigation features are Windows-only
- macOS artifact decryption is unavailable
- macOS Sigma coverage is narrower than Windows and Linux
Everything Xiaomi review
Forensicator: the full review
Forensicator provides cross-platform artifact collection and structured investigation output, with some features limited by operating system. Teams considering Enterprise should note that deployment and pricing details are not stated.
Forensicator is a live-response toolkit for collecting and analyzing system artifacts, best suited to incident responders and digital forensics teams. Its strongest case is turning endpoint evidence into searchable reports without requiring an installed agent; its analysis is less even across operating systems.
Overview
The collector runs from a cloned repository, with no agent or provisioning step. Full artifact access requires elevated permissions, so teams should account for privileged access when planning investigations. Each run produces a searchable HTML report and a structured investigation JSON folder; Windows also generates a case-summary JSON rollup.
The MIT-licensed collector is free and open source. For teams that need to upload, correlate, and manage reports centrally, Forensicator Enterprise is self-hosted software rather than a replacement for the collector.
Forensicator belongs in the broader Incident Response Software category, with a particular focus on live collection and artifact analysis.
Key features
- Sigma rules: It evaluates more than 1,400 community rules, but coverage and available data sources vary by operating system. Windows and Linux users get broader Sigma coverage than macOS users.
- Threat-intelligence matching: Malware hashes and indicators of compromise are checked against automatically updated feeds, including abuse.ch and URLhaus, adding a feed-based reference point to artifact review.
- Windows collection: Windows collection supports RAM acquisition through WinPmem and live network capture converted to PCAP for Wireshark. These are useful additions for investigations that need memory or traffic evidence, but the described capabilities are platform-specific.
- Encryption: Collected artifacts can be encrypted with AES. Decryption is supported on Windows and Linux, not macOS, a material constraint for teams that need to reopen encrypted evidence across platforms.
- AI investigation: On Windows, optional Forensicator AI can provide per-finding verdicts and a cross-finding summary with a risk score, timeline, and attack chain. Analysis can use local Ollama or commercial providers including OpenAI, Azure OpenAI, Anthropic, and OpenAI-compatible endpoints. Local-model support gives teams an offline option, but the AI investigation features are Windows-only.
Pricing
Forensicator: 0.00 USD per free. The free, open-source toolkit includes cross-platform incident-response collection. It is the clear fit for teams that can run the collector themselves and do not need centralized report management.
Forensicator Enterprise: custom pricing, billed by request a demo / contact sales. It is self-hosted and adds report uploading, correlation, and team management. Enterprise describes organization-scoped role-based access, hashed API keys, activity logging, configurable data retention, local-model support for offline AI analysis, an authenticated REST API, webhooks, and structured JSON export. Case management, evidence tracking, responder collaboration, audit logs, and API access are supported.
Platforms
Forensicator spans API, Linux, macOS, self-hosted, web, and Windows. That broad footprint does not mean feature parity: AI investigation, the Investigation Summary, and Active Directory, MSSQL, and SharePoint detection are Windows-only. macOS also has narrower Sigma coverage than Windows and Linux, and cannot decrypt encrypted artifacts.
Who it's for
The free collector suits responders who need live endpoint artifact collection and structured output, and can manage elevated access and operating-system-specific limits. Enterprise is aimed at security operations centers, incident response and digital forensics teams, and MSSPs that need to coordinate and correlate reports across teams. It is less suitable for organizations that require equivalent AI or detection coverage on every operating system.
Pros and cons
Pros
- Free, MIT-licensed collector: teams can use the toolkit without a paid collector plan.
- Useful investigation outputs: searchable HTML and structured JSON make findings easier to review and handle programmatically; Windows adds a case-summary rollup.
- Multiple AI provider options: Windows AI analysis can use local Ollama or commercial and compatible endpoints.
- Team controls in Enterprise: role-based access, activity logging, configurable retention, and API and webhook support address shared report workflows.
Cons
- Platform gaps matter: AI investigation and several detection areas are Windows-only, while macOS has narrower Sigma coverage and no artifact decryption.
- Elevated permissions are needed for full collection: access planning can complicate deployment in tightly controlled environments.
- Enterprise is self-hosted with custom pricing: teams must evaluate deployment and sales terms rather than choose a published price tier.
Alternatives
Choose LimaCharlie if you want a freemium option with a free tier for up to two endpoints, EDR included, and support across the same broad set of platforms.
ORNA is another option, with a self-managed free plan and a managed platform offered on custom quote.
Consider Binalyze AIR if you want a paid incident-response product with a free trial and support across Linux, macOS, and Windows as well as web, API, and self-hosted deployments.
Colander is a free alternative with Linux and self-hosted platform support.
Choose Autopsy for a free option available on Linux, macOS, and Windows.
DFIRe offers a freemium option, including case-by-case non-commercial access with all features for individual, student, educational, charity, and community use.
SandsBytes is another alternative.
TheHive is a freemium alternative available on Linux and web, with a self-hosted Community plan for two users and one organization.
Verdict
Forensicator is a strong fit for responders who want a free, agentless collector with substantial rule coverage, threat-intelligence matching, and usable investigation output. Choose it when Windows and Linux capabilities meet your needs and you can handle elevated collection access; look elsewhere if you need consistent macOS coverage or a published, straightforward Enterprise deployment and price.
Forensicator plans and pricing
All plansCompared on incident response software
- Free plan
- Yesforensicator.io
- Case management
- Yesforensicator.io
- Evidence tracking
- Yesforensicator.io
- Responder collaboration
- Yesforensicator.io
- Audit log
- Yesforensicator.io
- API access
- Yesforensicator.io
- Deployment options
- self_hostedforensicator.io
Facts
- Purpose
- Forensicator collects, analyzes, and interprets system artifacts during live investigations and produces structured HTML reports.opendocs.forensicator.io · 29 Sept 2026
- AI investigation
- Forensicator AI offers optional per-finding verdicts and a cross-finding summary with a risk score, timeline, and attack chain on Windows.opendocs.forensicator.io · 29 Sept 2026
- AI providers
- AI analysis can use local Ollama or commercial providers including OpenAI, Azure OpenAI, Anthropic, or an OpenAI-compatible endpoint.opendocs.forensicator.io · 29 Sept 2026
- Detection
- The toolkit evaluates more than 1,400 community Sigma rules, with coverage and data sources varying by operating system.forensicator.io · 29 Sept 2026
- Threat intelligence
- Malware hash and IOC matching uses auto-updating threat-intelligence feeds, including abuse.ch and URLhaus.opendocs.forensicator.io · 29 Sept 2026
- Collection features
- Windows collection includes RAM acquisition through WinPmem and live network capture converted to PCAP for Wireshark.forensicator.io · 29 Sept 2026
- Encryption
- Collected artifacts can be encrypted with AES; artifact decryption is available on Windows and Linux, but not macOS.opendocs.forensicator.io · 29 Sept 2026
- Reports and output
- Runs produce a searchable HTML report and a structured investigation JSON folder; Windows also produces a case-summary JSON rollup.opendocs.forensicator.io · 29 Sept 2026
- Setup
- The collector runs from a cloned repository without an agent or provisioning, and requires elevated permissions for full artifact access.forensicator.io · 29 Sept 2026
- Notable limits
- Forensicator AI, the Investigation Summary, and Active Directory/MSSQL/SharePoint detection are Windows-only; macOS Sigma coverage is narrower than on Windows and Linux.opendocs.forensicator.io · 29 Sept 2026
- Enterprise
- Forensicator Enterprise is self-hosted software for uploading, correlating, and managing collector reports across teams.forensicator.io · 29 Sept 2026
- Enterprise integrations
- Enterprise exposes an authenticated REST API, webhooks, and structured JSON export; specific SIEM, ticketing, or SOAR integrations are not listed.forensicator.io · 29 Sept 2026
- Security
- Enterprise describes organization-scoped role-based access, hashed API keys, activity logging, configurable data retention, and local-model support for offline AI analysis.forensicator.io · 29 Sept 2026
- Audience
- Enterprise is presented for security operations centers, incident response and digital forensics teams, and MSSPs.forensicator.io · 29 Sept 2026
- License
- The Forensicator collector is released under the MIT License.opendocs.forensicator.io · 29 Sept 2026
Best Forensicator alternatives
See all 12Where it ranks on Everything Xiaomi
Is Forensicator yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- opendocs.forensicator.io· checked 29 Sept 2026
- forensicator.io· checked 29 Sept 2026
- forensicator.io/enterprise· checked 29 Sept 2026




