Digital forensics Institution-led

DFIR-OGRE

Command-line parser that extracts Windows artefacts from DFIR ORC archives into structured records for analysis in search and analytics systems.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
Apache-2.0
Upstream status
Experimental
Evidence class
Institution-led

What the sources establish

Origin note

Managed by ANSSI and announced in its official open-source portfolio in May 2026.

Reported capabilities

  • Parses browser, file-system, process and Windows event artefacts in ORC archives.
  • Outputs structured data for Splunk, ELK or other stores.
  • Upstream README explicitly labels the project beta.

Scope and limits

Beta software with potentially breaking changes and unstabilized parsers; requires DFIR ORC archive input and a separate Windows parser plugin repository.

Inspect the research evidence 3 source observations
  1. identity / origin / country / capabilities / license / deployment / maintenance

    The ANSSI repository describes the command-line parser, archive input, supported artefact groups, installation, Apache-2.0 license, and its explicit beta state.

    Read source
  2. origin / maintenance

    ANSSI portfolio records publication of DFIR-OGRE on 21 May 2026 and identifies it as an agency project.

    Read source
  3. deployment

    Project documentation covers local command-line use and configuring parsers for ORC archives.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow