Digital forensics Institution-led
DFIR-OGRE
Command-line parser that extracts Windows artefacts from DFIR ORC archives into structured records for analysis in search and analytics systems.
By ANSSI · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- ANSSI
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- Apache-2.0
- Upstream status
- Experimental
- Evidence class
- Institution-led
What the sources establish
Origin noteManaged by ANSSI and announced in its official open-source portfolio in May 2026.
Reported capabilities
- Parses browser, file-system, process and Windows event artefacts in ORC archives.
- Outputs structured data for Splunk, ELK or other stores.
- Upstream README explicitly labels the project beta.
Scope and limits
Beta software with potentially breaking changes and unstabilized parsers; requires DFIR ORC archive input and a separate Windows parser plugin repository.
Inspect the research evidence 3 source observations
identity / origin / country / capabilities / license / deployment / maintenance
The ANSSI repository describes the command-line parser, archive input, supported artefact groups, installation, Apache-2.0 license, and its explicit beta state.
Read sourceorigin / maintenance
ANSSI portfolio records publication of DFIR-OGRE on 21 May 2026 and identifies it as an agency project.
Read sourcedeployment
Project documentation covers local command-line use and configuring parsers for ORC archives.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow