An independent tool index for incident response teams
Digital forensics / Institution-led
DFIR ORC
Windows forensic acquisition utility for collecting incident response artefacts from hosts into structured archives for later analysis and evidence handling.
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Uses configured YARA rules for file matching. In the documented 10.3.x scanner, blocks currently falls back to file-mapping behavior for compatibility; legacy block scanning can miss whole-file matches. Timeouts and scan-method limits apply.