The registry contains 80 tools: 79 READ_ONLY and 1 STATEFUL. The registry is
the source of truth for capability metadata; scripts/check_docs.py verifies this
summary against the loaded runtime.
Each tool also advertises a runtime readiness (runnable / degraded /
blocked) derived from its declared dependencies. Run dftk doctor to see how
many tools are runnable in your environment and dftk selftest to smoke-test
every runnable capability end-to-end.
evidence.intake— Agent-oriented evidence manifest, bounded SHA-256/magic inspection, and source-linked next-step plan for a file or extracted tree.artifact.inspect— magic/container-aware type identification + SHA-256.tree.inventory— bounded recursive inventory, extension distribution, largest files.file.hash— hashlib-backed cryptographic hashing.file.strings— printable ASCII strings with offsets.file.strings_unicode— UTF-16LE/BE printable strings with offsets.file.search_tree— literal/regex search across one file or an extracted tree.timeline.file_metadata— filesystem mtime/ctime/atime timeline.archive.inventory— ZIP/TAR member metadata without extraction.archive.extract_safe— policy-gated workspace extraction with traversal/size guards.timeline.merge— merge multiple event sources (dftk Observation JSON files or inline events) into one normalized, source-attributed timeline.
- DEX
string_data_itemparser with ULEB128/MUTF-8. - APK inventory and DEX search.
- binary AXML
AndroidManifest.xmlparsing. - package/version, permissions, SDK, application flags and component inventory.
- normalized URL/domain/IP/content-URI endpoint candidates from DEX strings.
- v1 signing-entry plus APK Signing Block v2/v3/v3.1 marker inventory.
- extracted app-data inventory, SharedPreferences parsing and database discovery.
- ELF architecture/section inventory.
- PE/COFF architecture, timestamp and section inventory.
- bounded JNI/crypto/network/command indicator string scan; explicitly heuristic.
- YARA rule scanning of one file or a bounded evidence tree, using either a rule file or inline rule source; source hashes, rule metadata, and bounded match offsets are retained without executing the sample.
- BIP39 English validation and evidence-tree scanning with checksum verification.
- Shannon entropy profiling by bounded blocks.
- hex/Base64/Base64URL/percent decoding candidates.
- offline OS/account/package-log/web-root/Docker discovery.
- package install/upgrade/remove events.
- SSH authentication and sudo log events.
- cron/systemd/authorized_keys/shell-history persistence candidates.
- offline Docker container config and json-file logs.
- web/application config candidate discovery and explicit config key/value extraction with secret redaction by default.
- Nginx/Apache access-log summaries.
- fixed-command read-only SSH inventory behind network policy.
- remote SSH forensic snapshot profiles for baseline, incident response, container, and web-server evidence: host key fingerprint, identity, sessions, processes, listeners, routes, systemd, timers, cron, persistence paths, auth-log tail, Docker, and web exposure—without an arbitrary command parameter.
- bounded WebShell hunting for PHP/JSP/ASP/ASPX/Node/Python source trees, with source hashes and byte offsets for suspicious input-to-execution/obfuscation combinations.
- immutable read-only SQLite schema/count inventory.
- bounded
SELECT/WITHSQLite query with engine-level authorizer. - generic SQL text-dump database/table/INSERT activity inventory.
- bounded cross-table/column literal search via
database.sqlite_search.
- classic PCAP flow inventory.
- PCAPNG SHB/IDB/EPB/SPB inventory for Ethernet IPv4 TCP/UDP.
- DNS question extraction.
- HTTP/1 request method/target/Host extraction.
- best-effort TLS ClientHello SNI extraction when the ClientHello is available in a single parsed TCP payload.
Optional python-registry / python-evtx capabilities:
- Registry hive inventory.
- SYSTEM hive CurrentControlSet USBSTOR and MountedDevices recovery.
- EVTX provider, EventID and timestamp summaries.
- Deep EVTX hunting: normalized event timeline plus high-value logon, process, PowerShell, service-install, scheduled-task, audit-clear, and Sysmon triage hits.
Optional forensic-environment capabilities:
- E01/EWF segment and acquisition metadata through
pyewf. - E01 partition/filesystem root inventory through
pyewf + pytsk3.
- Chromium/Chrome/Edge URL/visit history.
- Chromium download records and URL chains.
- Chromium cookie metadata, optional plaintext values, and encrypted-value hashes/lengths without decryption.
- Firefox
places.sqlitevisits.
- offline From/Sender/Return-Path/DKIM/Authentication-Results context.
- MIME structure and attachment SHA-256 inventory.
- network-gated DKIM verification and SPF evaluation.
correlation.entity_graph— source-linked domains, IPs, email addresses, SHA-256 values, and account identifiers across DFTK Observations; includes deterministic co-observation relationships.timeline.merge— pure correlation primitive: normalize ISO/epoch timestamps, sort, and attribute events to their source across multiple inputs.dftk case graph <case_id>/ MCPdftk_case(action="graph")— derive the same entity graph directly from persisted Case Observations.recipe.timeline.unified— compose a filesystem metadata timeline (and optional extra sources) into one unified timeline.dftk caseCLI — accumulate read-only tool runs in an isolated workspace (.dftk/cases/<id>/) and correlate them:case new,case list,case run,case timeline,case export(JSON or Markdown). The session only writes under its explicit workspace and never touches source evidence.
custody.ledger_verify— recompute the audit ledger's per-record SHA-256 hash chain and report records that were edited, deleted, reordered, truncated or downgraded; optionally compare the ledger against a seal. Read-only. A status ofokmeans the verification ran; readfacts.verdictfor the result.dftk audit verify <ledger.jsonl> [--seal seal.json]— the same check from the CLI. Exit 0 intact, 1 defective, 2 unreadable.dftk audit seal <ledger.jsonl>— write an external anchor (record count, last record hash, whole-file SHA-256) so deletion from the end of a ledger is detectable; a defective ledger refuses to seal.
recipe.artifact.auto_triagerecipe.android.static_triagerecipe.android.deep_static_triagerecipe.android.appdata_triagerecipe.server.offline_triagerecipe.server.deep_offline_triagerecipe.network.capture_triagerecipe.database.triagerecipe.windows.offline_triagerecipe.browser.history_triagerecipe.email.offline_triagerecipe.email.full_offline_triagerecipe.wallet.mnemonic_scanrecipe.timeline.unified— build a unified, source-attributed timeline from a filesystem tree plus optional extra dftk Observation sources.recipe.agent.guided_intake— one controlled Agent first-response call: evidence intake plus at most five eligible read-only, evidence-derived routes; it returns executed and deferred actions rather than guessing further commands.