Digital forensics Institution-led

DFIR ORC

Windows forensic acquisition utility for collecting incident response artefacts from hosts into structured archives for later analysis and evidence handling.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
LGPL-2.1
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

Managed by ANSSI, the French cybersecurity agency, with the repository explicitly naming ANSSI stewardship.

Reported capabilities

  • Collects forensic artefacts from Microsoft Windows systems.
  • Packages collections through a configurable Windows executable.
  • Current upstream release is v10.4.0.

Scope and limits

Windows-only collection tool. Its release notes concern forensic acquisition; no claim of evidentiary integrity certification is implied.

Inspect the research evidence 4 source observations
  1. identity / origin / country / capabilities / deployment

    The repository describes Windows forensic artefact collection, documents building the executable, and expressly says ANSSI manages the project.

    Read source
  2. license

    Upstream license is GNU Lesser General Public License 2.1.

    Read source
  3. maintenance

    Release v10.4.0 was published 8 October 2026 with collection and upload changes.

    Read source
  4. country

    ANSSI organization profile identifies its repositories as agency-developed projects and its French national agency role.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

YARA Capability

Uses configured YARA rules for file matching. In the documented 10.3.x scanner, blocks currently falls back to file-mapping behavior for compatibility; legacy block scanning can miss whole-file matches. Timeouts and scan-method limits apply.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow