Free Digital Forensics Tools

Here you will find practical, field-tested tools built to support digital forensic work. From iOS backup normalization to VarInt decoding, these utilities help you work faster and more precisely. We update the collection regularly. Want to stay informed about new tools and updates? Fill in your email below, and we’ll keep you posted.
free tool

Backup 2FS. Recover and normalize files from iOS backups.

Backup 2FS is a free Windows tool that helps you recover and normalize files from iOS backups. Extract user data, organize backup contents into a readable file system, and verify file integrity using hash algorithms like MD5, SHA-1, and SHA-256. Built for forensic examiners who need clarity and structure when working with raw backup data.

free tool

VarInt Calculator. A tool for calculating and decoding VarInts.

VarInt Calculator is created to simplify a niche but critical part of mobile artifact analysis. It is a lightweight Windows tool for calculating and decoding VarInts, variable-length integers commonly used in mobile app databases and messaging protocols.

With VarInt Calculator, you can:

• Convert hex values to VarInt and vice versa
• Instantly see binary and decimal interpretations
• Understand field sizes in protobufs and custom database formats
• Save time during manual validation and reverse engineering

VarInt Calculator
news and articles

Latest news and articles

Dive into our curated articles, case studies, and guides designed to empower forensic professionals with the latest techniques and industry developments.

New Free Tool Release: Backup2FS – Normalize iOS Backups for Easier Analysis

New Free Tool Release: Backup2FS – Normalize iOS Backups for Easier Analysis

Discover Backup2FS, a free tool from Elusive Data that simplifies iOS backup analysis by normalizing backups into an easy-to-navigate file system.

New Free Tool Release: VarInt Calculator – Simplify Mobile Artifact Analysis

New Free Tool Release: VarInt Calculator – Simplify Mobile Artifact Analysis

Instantly decode VarInts from mobile app databases with Elusive Data’s free forensic tool. Convert hex, binary, and decimal values for faster, more accurate investigations.

Decrypt Locked Apple Notes on iOS 16.x: A Complete Forensic Workflow (SQLite, CyberChef, Python) Featuring Hashcat

Decrypt Locked Apple Notes on iOS 16.x: A Complete Forensic Workflow (SQLite, CyberChef, Python) Featuring Hashcat

Discover how I decrypted a locked Apple Note from an iOS 16.7.10 device using open-source tools like Hashcat, Python, and CyberChef. This step-by-step forensic workflow reveals the process behind extracting and decrypting hidden content from Apple’s Notes app. A must-read for digital investigators and mobile forensics professionals.

stay updated

Stay in the loop. Sign up for our monthly newsletter.

Be the first to hear about new training opportunities, free tools, case-based blog posts, and practical insights. Our monthly newsletter is built to help you learn faster, solve cases smarter, and keep up in a field that never stands still.

Fill in your email to sign up.