Skip to main content

DFTK — Digital Forensics Toolkit

CI License Python PyPI

DFTK is a Python toolkit for evidence-preserving digital-forensics operations. It provides structured results for files, archives, mobile artifacts, databases, captures, browser data, email, host artifacts, and timelines.

中文说明见 README.zh-CN.md.

Install

pip install dftk

Optional integrations:

pip install "dftk[email]"    # DKIM / SPF / DNS
pip install "dftk[ssh]"      # read-only SSH inventory
pip install "dftk[windows]"  # Registry / EVTX parsers
pip install "dftk[yara]"     # YARA rule scanning
pip install "dftk[mcp]"      # local MCP server
pip install "dftk[all]"      # all optional Python integrations

The core package has no mandatory third-party runtime dependencies. E01 filesystem traversal additionally requires pyewf / libewf bindings and pytsk3.

Start here

# Discover available capabilities
dftk list

# Build an Agent-ready intake manifest and next-step plan
dftk run evidence.intake --params '{"path":"/evidence/acquisition"}'

# Inspect one capability before running it
dftk describe artifact.inspect

# Analyze an artifact
dftk run artifact.inspect --params '{"path":"sample.apk"}'

# Save related observations in a case
dftk case --workspace /cases/intake new --name intake
dftk case --workspace /cases/intake run <case_id> artifact.inspect --params '{"path":"sample.apk"}'
dftk case --workspace /cases/intake export <case_id> --format md

Each run returns an Observation with a status, facts, evidence, warnings, and errors. unsupported, error, and blocked describe limitations or failures; they are not negative findings.

Agent and MCP use

For Agent use, the recommended entry point is this DFTK repository: give its URL to the Agent. It installs DFTK first, then runs a single bounded bootstrap that fetches the matching complete DFTK-skill bundle and emits a reviewable MCP configuration fragment:

dftk agent setup --root /evidence/acquisition --workspace /cases/intake --install-skill

See INSTALL_AGENT.md for the paste-ready instruction and AGENT_INTEGRATION.md for the complete operating loop.

DFTK includes a local stdio MCP server. Keep acquired evidence read-only and use a separate writable case workspace:

pip install "dftk[mcp]"
dftk mcp --root /evidence/acquisition --workspace /cases/intake --check
dftk mcp --root /evidence/acquisition --workspace /cases/intake

The server defaults to READ_ONLY with network access disabled. Its launch options define the evidence root, safety ceiling, network access, and timeout. See the MCP guide for configuration and policy details.

For an existing host configuration, install the matching Skill bundle directly:

dftk skill --install  # auto-detect the current Agent host; portable fallback: agents
# Inspect all supported target paths before a broad installation:
dftk skill --install --target all --dry-run

Documentation

Project facts

DFTK supports lawful, authorized examination of evidence. It is a technical toolkit, not legal advice.

Metadata

Release files for dftk 3.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dftk 3.4.0
File Size Uploaded
dftk-3.4.0.tar.gz 178.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dftk 3.4.0
File Interpreter ABI Platform
dftk-3.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 328.6 kB

Release files / dftk-3.4.0.tar.gz

Download URL dftk-3.4.0.tar.gz
Size 178.3 kB
Tags Source
SHA-256 checksum
How to use checksums
acdb63cf7a9c74c1e2ee71993106b24a8888b0ac713c4d29020d80fb03b1a14e
BLAKE2b-256 checksum
How to use checksums
969f5f5e58d9ce19799a2cee08b01f22206da9097b6297334c8566f61683dc6d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / dftk-3.4.0-py3-none-any.whl

Download URL dftk-3.4.0-py3-none-any.whl
Size 150.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e92e09e375e9b5a2d554b41ddcc12d96ff53358fd0ebb7e431e4459604feca74
BLAKE2b-256 checksum
How to use checksums
f5837880a73384b378810b14613d349a83cf715a665ed2452a0ff5db0cf0640c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.4.0 This release

2 release files

3.3.0

2 release files

3.2.1

2 release files

3.1.1

2 release files

3.1.0

2 release files

3.0.0

2 release files

2.1.1

2 release files

2.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page