# fox-it/dissect

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group).

Repository: https://github.com/fox-it/dissect
Canonical: https://ross.abutalabs.com/products/dissect
Homepage: https://docs.dissect.tools/en/latest/
License: AGPL-3.0
License Family: copyleft
Topics: dfir, dissect, python
Last push: 2026-02-25T14:09:37+00:00

## Health v2 (maintenance only)
Score: 72/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 69, release rhythm 60, longevity 100
- inputs: {"age_days": 1504, "days_push": 189, "days_rel": 188, "gap_med": 76.0, "n_releases_24m": 9}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1148, forks 85 (observed 2026-08-28T04:03:46.173703+00:00)

## What it is
Dissect is a modular digital forensics and incident response (DFIR) framework and toolset by Fox-IT that parses forensic artefacts from many disk image, container, filesystem, and OS formats. It provides tools like target-query and target-shell for uniform access to artefacts, plus Acquire for lightweight endpoint acquisition.

## Use cases
- parse Windows Event Logs from an E01 disk image
- extract MFT entries from a VMDK or QCoW without mounting
- collect forensic artefacts from endpoints with Acquire
- analyse Runkeys and Prefetch files from a Linux or Windows image
- build custom DFIR tooling from modular parser libraries
- triage running VMs on a hypervisor

## When to choose
- you need a single unified tool to parse artefacts across disk formats, filesystems, and operating systems
- you want scriptable, modular Python libraries for forensic parsing
- you need to acquire lightweight forensic images from live endpoints or hypervisors

## When to avoid
- you need a GUI-based forensic suite with visual timeline analysis
- you require a license more permissive than AGPL-3.0 for commercial embedding
- you only need one-off parsing of a single well-supported file format with a simpler tool

## Facets
- artifact type: framework
- maturity: active
- function: parser, file-system, cli, security
- domain: security, developer-tools
- platform: python, cli, windows, cross-platform
- tags: dfir, incident-response, digital-forensics, disk-images, artifact-parsing, target-query, target-shell, acquire, forensics, command-line, linux, macos

## Member repositories
- fox-it/dissect (main) score 72

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:46.173703+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:33:50.092521+00:00, confidence not recorded.
  - readme: https://github.com/fox-it/dissect (fetched 2026-08-28T04:03:46.173703+00:00, sha 04c5013f3cb9)
  - registry_pypi: https://pypi.org/pypi/dissect/json (fetched 2026-08-29T12:39:48.278190+00:00, sha b30a967faaca)
- Data as of 2026-08-30T08:39:29.467469+00:00.
