DFIR and CTF forensics workflow — file/disk triage, memory analysis with Volatility3, network artifacts, and Windows evidence. (20 payloads)
file suspicious.binbinwalk -e firmware.binforemost -i image.dd -o carved/photorec image.ddstrings -e l -n 8 file.binvol -f mem.raw windows.infovol -f mem.raw windows.pslistvol -f mem.raw windows.netscanvol -f mem.raw windows.cmdlinevol -f mem.raw windows.dumpfiles --pid 1337vol -f mem.raw linux.bash.Bashtshark -r capture.pcap -q -z conv,tcptshark -r capture.pcap --export-objects http,out/zeek -r capture.pcaprip.pl -r NTUSER.DAT -f ntuserPECmd.exe -d C:\\Windows\\PrefetchMFTECmd.exe -f $MFT --csv outEvtxECmd.exe -d C:\\Windows\\System32\\winevt\\Logs --csv outlog2timeline.py timeline.plaso image.dd && psort.py -o l2tcsv timeline.plasosha256sum evidence.ddLevel up your security testing
Install the CLI
npx payload-playgroundExplore All Tools
Encoding, hashing, JWT & more
Browse Cheat Sheets
Quick-reference payload guides
It's a quick-reference collection of 20 Forensics payloads for testing Digital Forensics vulnerabilities during authorized penetration testing, bug bounties, and CTFs. Every payload is copy-ready and grouped by attack context.
Copy any payload straight into your authorized test, or use the What Is This? to apply them interactively. Only test systems you have explicit permission to assess.
Yes — this cheat sheet and all Forensics payloads are completely free, with no account required. Everything runs in your browser.