ECIH 工具表
本篇整理 ECIH 課程中提到的工具,依照「實際功能」分類,方便事件處理時快速查找。
整理原則:同一工具只放在一個主要功能分類中。若工具同時具有其他用途,會直接寫在「主要用途/備註」中,不另外重複列一遍。
ECIH Incident Handling 工具總表
1. AI 輔助 DFIR / Malware Analysis
| 工具 |
主要用途 |
主要系統 / 資料 |
費用 / 授權 |
備註 |
| REMnux MCP Server |
AI 自動挑選 Malware Analysis 工具、執行分析、抽 IOC、整理報告 |
REMnux / Malware Samples |
GPL-3.0 |
AI Malware Analysis |
| Mecha Hayabusa |
AI 查 Windows Event Log、Timeline、IOC、橫向移動、IR Report |
Hayabusa / EVTX |
AGPLv3 |
Hayabusa 的 AI 輔助分析 |
| GhidrAssist |
在 Ghidra 中使用 LLM 解釋 Function、Rename、RAG、Agent 分析 |
Binary / Ghidra |
MIT |
Reverse Engineering AI |
| GhidrAssistMCP |
讓 AI Agent 直接操作 Ghidra |
Binary / Ghidra |
Open Source |
MCP 整合 |
| r2ai / decai |
AI + radare2,解釋、Decompiler、Rename、弱點分析 |
Binary |
MIT |
Reverse Engineering AI |
| Senrigan |
AWS CloudTrail DFIR、Threat Hunting、Dashboard、AI Chat |
AWS CloudTrail |
AGPLv3 |
Cloud DFIR |
| OpenCode + REMnux |
通用 AI Agent 搭配 REMnux MCP 執行 Malware Analysis |
REMnux |
Open Source |
AI Agent 工作流 |
2. Endpoint Triage / Live Response / 主機現場調查
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| Velociraptor |
遠端蒐證、Endpoint Triage、Threat Hunting、Incident Response |
Windows / Linux / macOS |
免費開源 |
大規模端點調查 |
| osquery |
用 SQL 查 Process、Network、Driver、Hash、User 等 Endpoint 狀態 |
Windows / Linux / macOS |
免費開源 |
快速盤點主機狀態 |
| TCPView |
查看 TCP / UDP 連線、對應 Process、Local / Remote IP |
Windows |
免費 |
Sysinternals |
| Process Explorer |
Process、Parent/Child Process、Handle、DLL 等調查 |
Windows |
免費 |
Sysinternals |
| Process Monitor |
即時監控 Process、File、Registry、Network 等活動 |
Windows |
免費 |
Malware 動態調查常用 |
| Autoruns |
查看開機與登入自動啟動項目、Persistence |
Windows |
免費 |
Sysinternals |
| Regshot |
比較 Registry 修改前後差異 |
Windows |
免費 / 開源 |
Malware 行為分析 |
| jv16 PowerTools |
Windows Registry、Startup、Software、File 等系統管理與檢查 |
Windows |
付費 / 試用 |
可輔助檢查 Registry / Startup;非專用 DFIR 工具 |
| Sigcheck |
驗證數位簽章、Hash、檔案資訊 |
Windows |
免費 |
Sysinternals |
| Sigverif |
掃描 Windows 系統檔案與 Driver 的 Digital Signature,找出未簽章檔案 |
Windows |
內建 / 免費 |
Windows File Signature Verification;與 Sigcheck 功能相近但用途不同 |
| netstat |
查看 TCP/UDP Connection、Listening Port、Route 等 |
Windows / Linux |
內建 / 免費 |
Linux 現代環境多改用 ss |
| ss |
查看 Socket、TCP / UDP 連線與 Listening Port |
Linux |
內建 / 免費 |
現代 Linux 常用 |
| lsof |
查看 Process 開啟的檔案、Socket、Network Connection |
Linux / Unix |
免費開源 |
找可疑 Process 很實用 |
| ps aux |
查看目前執行中的 Process |
Linux / Unix |
內建 / 免費 |
主機 Triage 基本指令 |
| lastlog |
查看帳號最後登入時間 |
Linux |
內建 / 免費 |
帳號事件調查 |
| w / who |
查看目前登入使用者與 Session |
Linux / Unix |
內建 / 免費 |
Session 調查 |
| rwho |
查看區網內其他 Unix 主機登入資訊 |
Linux / Unix |
免費 |
較舊式工具 |
| nbtstat |
查看 NetBIOS over TCP/IP 名稱與快取資訊 |
Windows |
內建 / 免費 |
Windows 網路調查 |
3. Memory Forensics / 記憶體鑑識
| 工具 |
主要用途 |
主要系統 / 資料 |
費用 / 授權 |
備註 |
| Volatility 3 |
RAM / Memory Forensics、Process、DLL、Network、Malware Artifact 分析 |
Windows / Linux / macOS Memory |
免費開源 |
DFIR 核心工具 |
4. Malware 靜態分析 / Reverse Engineering
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| YARA / YARA-X |
依 Pattern、String、Binary 特徵偵測 Malware |
Windows / Linux / macOS |
免費開源 |
YARA-X 為新一代實作 |
| capa |
自動判斷 Binary 可能具備的 Capability / 行為能力 |
Windows / Linux / macOS |
免費開源 |
快速理解 Malware 能做什麼 |
| FLOSS |
擷取 Malware 中被 Obfuscate / Encode 的字串 |
Windows / Linux / macOS |
免費開源 |
比一般 strings 更適合 Malware |
| Ghidra |
Disassembly、Decompiler、Reverse Engineering |
Windows / Linux / macOS |
免費開源 |
逆向分析核心工具 |
| Cutter |
GUI Reverse Engineering、Disassembly、Decompiler |
Windows / Linux / macOS |
免費開源 |
基於 Rizin |
| Detect It Easy (DIE) |
判斷 PE / ELF 格式、Compiler、Packer、Protector |
Windows / Linux / macOS |
免費開源 |
Malware 初步辨識 |
| strings |
從 Binary 擷取可讀字串 |
Windows / Linux / macOS |
免費 |
靜態分析基本工具 |
| HashMyFiles |
快速計算 MD5 / SHA 等檔案 Hash |
Windows |
免費 |
IOC / Hash 比對 |
| readelf |
查看 ELF Header、Section、Symbol 等資訊 |
Linux |
內建 / 免費 |
Linux Malware 靜態分析 |
| olevba |
分析 Office 文件 VBA Macro |
Windows / Linux / macOS |
免費開源 |
Office Malware 常用 |
| CyberChef |
Base64、Hex、XOR、壓縮、編解碼、資料轉換 |
Browser / 跨平台 |
免費開源 |
IOC / Payload 解碼常用 |
5. Malware 動態分析 / Sandbox / Instrumentation
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| CAPEv2 |
自動化 Malware Sandbox、動態行為分析、Config / Payload Extraction |
Linux Host + Windows Guest |
免費開源 |
自架 Malware Sandbox |
| Frida |
Dynamic Instrumentation、Hook Function / API |
Windows / Linux / macOS / Android / iOS |
免費開源 |
動態分析與逆向 |
| strace |
追蹤 Process 的 System Call |
Linux |
免費 |
Linux Malware 動態分析 |
6. Malware / DFIR 分析環境
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| REMnux |
整合大量 Linux Malware Analysis 工具 |
Linux |
免費開源 |
Malware Analysis Distribution |
| FLARE-VM |
Windows Reverse Engineering / Malware Analysis 工具整合環境 |
Windows VM |
免費開源 |
Windows Malware Analysis Lab |
7. Network Discovery / 網路探索與基本診斷
| 工具 / 指令 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| Nmap |
Host Discovery、Port Scan、Service / OS Detection、NSE Script |
Windows / Linux / macOS |
免費開源 |
NSE sniffer-detect 亦可協助偵測 Promiscuous Mode |
| ping |
測試主機可達性、延遲與封包遺失 |
全平台 |
內建 / 免費 |
基本連線診斷 |
| tracert |
追蹤封包到目的地主機的路由 |
Windows |
內建 / 免費 |
Windows 指令 |
| traceroute |
追蹤封包路由 |
Linux / Unix |
免費 |
Linux / Unix |
| tracepath |
路由與 Path MTU 診斷 |
Linux |
免費 |
不一定需要 root |
| mtr |
結合 ping + traceroute 持續觀察路由與 Loss |
Linux / Unix |
免費開源 |
長時間網路診斷 |
| ARP / arp |
查看與管理 ARP Cache、IP-MAC Mapping |
Windows / Linux |
內建 / 免費 |
ARP 調查基礎 |
| ifconfig |
查看 / 設定 Network Interface |
Linux / Unix |
免費 |
現代 Linux 多改用 ip |
| dig |
DNS Query 與 DNS 故障排除 |
Linux / Unix |
免費 |
DNS 調查常用 |
| nslookup |
DNS Query |
全平台 |
內建 / 免費 |
快速 DNS 查詢 |
8. Packet Capture / Network Traffic / Protocol Analysis
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| Wireshark |
Packet Capture、Protocol Analysis、PCAP 調查 |
Windows / Linux / macOS |
免費開源 |
封包分析核心工具 |
| tcpdump |
CLI Packet Capture、BPF Filter、PCAP 擷取 |
Linux / Unix |
免費開源 |
Server / CLI 常用 |
| Zeek |
Network Security Monitoring、Protocol Parsing、產生結構化 Network Log |
Linux / Unix 為主 |
免費開源 |
可分析 SMB、DCE-RPC、DNS、HTTP 等 |
| Suricata |
IDS / IPS / Network Security Monitoring、Rule Detection |
Linux / Windows |
免費開源 |
可搭配 Zeek / PCAP |
| Arkime |
大量 PCAP 儲存、索引、Session Search |
Linux Server |
免費開源 |
適合長期封包留存 |
| CapLoader |
大型 PCAP / PcapNG 索引、TCP/UDP Flow 檢視、快速篩選與匯出封包 |
Windows |
免費 Trial + 付費版 |
適合大量 PCAP;可把選定 Flow 送到 Wireshark / NetworkMiner |
| Malcolm |
整合 Zeek、Suricata、Arkime 等進行 Network Traffic Analysis |
Linux / Docker |
免費開源 |
一體化 Network DFIR 平台 |
| ntopng |
即時 Network Traffic、Host、Protocol、Flow 分析 |
Linux / Server |
Community 免費 + 付費版 |
Web UI |
| NetHogs |
按 Process 查看網路頻寬使用量 |
Linux |
免費開源 |
找異常流量 Process |
| Colasoft Capsa / Capsa Portable Network Analyzer |
Packet / Protocol / Traffic Analysis |
Windows |
免費版 + 付費版 |
將教材中的 Colasoft Network Analyzer / Capsa 合併 |
| OmniPeek |
專業封包、Protocol、Network Performance Analysis |
Windows |
付費 |
商用工具 |
| Observer Analyzer |
Packet Analysis、Network Performance、故障診斷 |
Windows / Appliance |
付費 |
商用工具 |
| NetScanTools Pro |
Packet Capture、Subnet Scan、Promiscuous Mode Scanner 等網路調查功能 |
Windows |
付費 / Demo |
將教材中的 Packet Capture 與 Promiscuous Mode Scanner 合併 |
9. NetFlow / Network Monitoring / Network Behavior Analysis
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| SolarWinds NetFlow Traffic Analyzer |
NetFlow / Flow 流量、頻寬、Top Talker 與應用流量分析 |
Windows Server / Web |
付費 / 試用 |
Flow Monitoring |
| ManageEngine NetFlow Analyzer |
NetFlow、sFlow、IPFIX 流量與頻寬分析 |
Windows / Linux Server |
有免費版 / 付費版 |
教材中的 NetFlow Analyzer 同項合併 |
| Cisco Stealthwatch / Secure Network Analytics |
Network Behavior Analytics、Flow-based Detection、異常行為分析 |
Appliance / Server |
付費 |
Stealthwatch 為教材舊名稱 |
| PRTG Network Monitor |
SNMP、Flow、Device、Service、Bandwidth Monitoring |
Windows Server / Web |
免費額度 + 付費版 |
綜合網路監控 |
| Nagios XI |
Network、Host、Service Availability Monitoring |
Linux Server |
付費 / 試用 |
基礎架構監控 |
10. Log Collection / SIEM / Event Analysis
| 工具 / 功能 |
主要用途 |
主要系統 / 資料 |
費用 / 授權 |
備註 |
| Hayabusa |
Windows EVTX 快速分析、Timeline、Sigma Hunting |
Windows EVTX;工具可跨平台執行 |
免費開源 |
Windows Event Log DFIR |
| Chainsaw |
EVTX、MFT、Shimcache、SRUM 等 Windows Artifact 快速 Triage |
Windows / Linux / macOS |
免費開源 |
Artifact Analysis |
| Plaso / log2timeline |
建立 Forensic Super Timeline |
跨平台 |
免費開源 |
多來源時間線建立 |
| Timesketch |
多來源 Timeline 分析、搜尋與協作式 Forensics |
Web / Linux Server |
免費開源 |
常搭配 Plaso |
| IIS Logging |
保存 Web Request:來源 IP、URL、HTTP Method、Status、User-Agent |
Windows Server / IIS |
IIS 內建 |
Web Incident Investigation |
| pfSense System Logs |
Firewall Allow/Block、Source / Destination IP、Port、Protocol 等 |
pfSense / FreeBSD |
內建 |
Firewall Log |
| ManageEngine EventLog Analyzer |
集中收集 Windows、Linux、Firewall、IIS、Mail 等 Log,搜尋與關聯分析 |
Windows / Linux Server + Web |
有免費版 |
Log Management / SIEM |
| Kiwi Syslog Server |
集中接收與查看 Syslog、SNMP Trap、Windows Event 等 |
Windows |
付費 / 試用 |
Syslog Server |
| ManageEngine Log360 |
SIEM、Log Management、AD Security、事件關聯 |
Windows / Linux / Web |
付費 / 試用 |
SIEM 平台 |
| Rapid7 InsightOps |
Cloud Log Management、Search、Alert、Event Analysis |
SaaS |
付費 |
Cloud Log Analytics |
| Splunk Enterprise Security |
SIEM、Event Correlation、Alert、Threat Hunting |
Server / Web |
付費 |
Enterprise SIEM |
| Logz.io |
Cloud Log Analytics、SIEM、Observability |
SaaS |
商用 |
Cloud 平台 |
| Graylog |
集中 Log 收集、搜尋、Pipeline、Stream、Alert |
Linux / Docker / Server |
Open + Enterprise |
自架 Log 平台 |
11. Detection Rules / Threat Intelligence / IOC 管理
| 工具 |
主要用途 |
主要系統 / 資料 |
費用 / 授權 |
備註 |
| Sigma |
通用 Log Detection Rule,可轉換成不同 SIEM Query |
跨平台 / SIEM |
免費開源 |
Detection Engineering 常用 |
| MISP |
IOC / Threat Intelligence 收集、管理與分享 |
Server / Web |
免費開源 |
IOC Sharing |
| OpenCTI |
CTI Knowledge Graph、IOC / TTP / Threat Actor 關聯 |
Server / Web |
免費開源 |
Threat Intelligence Platform |
12. Vulnerability Assessment / Vulnerability Management
| 工具 |
主要用途 |
主要系統 / 形式 |
費用 / 授權 |
備註 |
| SanerNow |
Vulnerability Assessment、Patch Management、Asset Management |
SaaS / Endpoint Agent |
付費 |
SecPod |
| Rapid7 Nexpose |
主機、服務與網路弱點掃描、Risk Assessment |
Server / Web |
付費 / 試用 |
Rapid7 |
| Tenable.io / Tenable Vulnerability Management |
Cloud-based Vulnerability Management |
SaaS |
付費 |
Tenable.io 為教材名稱 |
| Qualys |
Vulnerability Management、Asset Inventory、Cloud Security |
SaaS |
商用 |
SaaS 弱點管理 |
| Nessus |
Host、Service、Configuration、CVE Vulnerability Scan |
Windows / Linux / macOS |
Essentials 免費 + Professional 付費 |
常見弱掃工具 |
| GFI LanGuard |
Vulnerability Scan、Patch Management、Asset Discovery |
Windows |
付費 / 試用 |
Windows 環境常見 |
| Intruder |
Cloud Vulnerability Scanning、Attack Surface Monitoring |
SaaS |
付費 / 試用 |
SaaS |
| OpenVAS / Greenbone Community Edition |
Network / Host Vulnerability Scanning |
Linux / Server |
免費開源 |
OpenVAS 屬 Greenbone 生態系 |
13. ARP Poisoning / Spoofing / Sniffer Detection
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| ArpON |
ARP Spoofing / MITM Detection 與防護 |
Linux |
免費開源 |
教材工具,較舊 |
| ARP AntiSpoofer |
ARP Spoofing Detection |
Windows / Linux |
免費 |
教材工具,較舊 |
| ARPStraw |
ARP 異常 / Spoofing Detection |
Linux |
開源 |
小型專案 |
| shARP |
ARP Spoofing Detection |
Linux |
開源 |
小型專案 |
| ARPShield |
ARP Poisoning Detection / Protection |
Linux |
開源 |
教材工具,較舊 |
Promiscuous Mode Detection 不再另外重複列工具:Nmap 可使用 NSE sniffer-detect;NetScanTools Pro 具 Promiscuous Mode Scanner。兩者已分別放在「Network Discovery」與「Packet Capture / Network Traffic」分類中。
14. Incident Case Management / 調查協作
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| DFIR-IRIS |
Incident Case Management、Evidence、IOC、Timeline 與 Team Collaboration |
Server / Web |
免費開源 |
DFIR 案件管理平台 |
| 工具 |
主要用途 |
主要系統 / 形式 |
費用 / 現況 |
備註 |
| EmailSherlock |
用 Email 查詢公開資訊、帳號與網路足跡 |
Web |
Web 服務 |
OSINT 類用途 |
| Google Admin Toolbox – Messageheader |
分析 Email Header、Received Path、SMTP Relay、郵件延遲 |
Web |
免費 |
Header Analysis |
| DNSChecker – Email Header Analyzer |
解析 Header、追查 Mail Server / IP 路徑 |
Web |
免費 |
Header Analysis |
| MXToolbox |
查 MX、SMTP、SPF、DKIM、DMARC、Blacklist、Header |
Web |
部分免費 |
郵件與 DNS 調查常用 |
| Trace Email – WhatIsMyIPAddress |
從 Header 找 Source IP,再做 GeoIP / Source Analysis |
Web |
免費 |
Email Tracking |
| Email Tracer – IPAddressLocation.org |
Email Header / IP 來源追蹤與 GeoIP 查詢 |
Web |
Web 工具 |
Email Tracking |
16. System Resource / Performance Monitoring
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| AIDA64 Extreme |
CPU、Memory、Hardware Sensor、System Performance Monitoring |
Windows |
付費 / 試用 |
教材用於高資源使用調查 |
| HWiNFO |
Hardware Inventory、Sensor、CPU / GPU / Temperature Monitoring |
Windows |
個人免費 + 商用授權 |
硬體監控 |
| OCCT |
CPU / GPU / RAM Stress Test 與 Resource Monitoring |
Windows |
個人免費 + 商用版 |
壓力測試 |
| InsightCat |
Server / System Performance Monitoring |
Server / Web |
商用 |
教材工具 |
| SysGauge |
CPU、RAM、Disk、Network Performance Monitoring |
Windows |
免費版 + 付費版 |
系統監控 |
| HWMonitor |
CPU / GPU Temperature、Voltage、Fan Sensor Monitoring |
Windows |
免費版 + Pro |
硬體 Sensor |
17. Linux / Unix 基礎鑑識與資料處理指令
| 指令 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| dd |
Bit-level Data Copy、Disk / Image Acquisition |
Linux / Unix |
內建 / 免費 |
可用於基礎磁碟映像 |
| grep |
搜尋 Log、IOC、Keyword、Regular Expression |
Linux / Unix |
內建 / 免費 |
Log Investigation 基本工具 |
| cat |
顯示 / 串接 Text、Log File |
Linux / Unix |
內建 / 免費 |
基礎指令 |
18. Web Application Firewall / WAAP / Web Attack Protection
| 工具 |
主要用途 |
主要形式 |
費用 / 現況 |
備註 |
| AppTrana WAF |
Web Application / API Protection、WAF、Bot / DDoS 防護 |
Cloud / SaaS |
付費 / 試用 |
Indusface;目前產品定位已延伸至 WAAP |
| FortiWeb |
WAF、HTTP/HTTPS Application-layer Protection、Web Attack Detection |
Appliance / VM / Cloud |
付費 |
Fortinet WAF |
| StackPath SP//WAF |
Web Application Firewall、Edge-based Web Protection |
Cloud / Edge |
已停止服務 |
教材舊工具;StackPath WAF 於 2024 年 EOL |
| F5 Advanced WAF |
Web / API Application Security、Bot、Credential Abuse、Application DoS 防護 |
Appliance / VM / Cloud |
付費 |
F5 BIG-IP Advanced WAF |
| Barracuda Web Application Firewall |
Web / API Protection、OWASP 攻擊、Bot、Application-layer DDoS 防護 |
Appliance / VM / Cloud |
付費 / 試用 |
Barracuda Application Protection |
這五項屬於同一功能類別的不同產品,不是重複項目,因此集中在同一張 WAF 表中。
19. Honeypot / Deception / Intrusion Detection
| 工具 |
主要用途 |
主要系統 |
費用 / 授權 |
備註 |
| KFSensor |
模擬 Vulnerable Services / Trojan Services,誘捕並記錄 Port Scan、攻擊與入侵行為 |
Windows |
付費 / 試用 |
Windows Honeypot IDS;與 Suricata 不同,核心是 Decoy / Honeypot |
快速查找
| 事件 / 需求 |
工具 |
| 主機是否有異常 Process / Connection |
Process Explorer、TCPView、Process Monitor、osquery、Velociraptor |
| Windows Event Log 調查 |
Hayabusa、Chainsaw |
| Memory Dump 調查 |
Volatility 3 |
| 可疑 Binary 靜態分析 |
YARA / YARA-X、capa、FLOSS、DIE、Ghidra |
| Malware 動態行為 |
CAPEv2、Frida、Process Monitor、strace |
| Network / Port Discovery |
Nmap |
| 即時 Packet / PCAP 分析 |
Wireshark、tcpdump |
| 大型 PCAP 快速索引 / Flow 篩選 |
CapLoader |
| 大量 Network Traffic / Session Investigation |
Zeek、Arkime、Malcolm |
| IDS / Network Detection |
Suricata |
| Flow / Bandwidth / Top Talker |
ManageEngine NetFlow Analyzer、SolarWinds NTA、ntopng |
| Syslog / 集中 Log Search |
Graylog、Kiwi Syslog Server、ManageEngine EventLog Analyzer |
| Enterprise SIEM |
Splunk Enterprise Security、ManageEngine Log360 |
| Forensic Timeline |
Plaso / log2timeline、Timesketch |
| IOC / Threat Intelligence |
MISP、OpenCTI |
| Vulnerability Scan |
OpenVAS、Nessus、Nexpose、Qualys |
| Web Application Firewall / Web Attack Protection |
AppTrana WAF、FortiWeb、F5 Advanced WAF、Barracuda WAF |
| Honeypot / Decoy / 入侵誘捕 |
KFSensor |
| Email / Phishing Header |
Google Messageheader、MXToolbox、DNSChecker |
| ARP Spoofing / MITM |
ArpON 等;實務也可搭配 Wireshark / IDS 觀察 |
| SMB 可疑活動 |
Zeek(SMB / DCE-RPC Logs) |
| 高 CPU / RAM / Hardware Resource |
HWiNFO、AIDA64、SysGauge、HWMonitor |