Install Eric Zimmerman's forensics tools on Linux

Aug 7, 2024 by Thibault Debatty | 1851 views

Forensics Linux

In a previous blog post, I presented the forensics tools written by Eric Zimmerman. Although these tools were originally developed for Windows, you can also run them on a Linux. This allows to run a full forensic investigation using a Linux computer.

Eric Zimmerman is a former Special Agent with the FBI and a renowned digital forensics expert, who developed a collection of tools to assist forensics analysts. The tools cover a broad spectrum of forensic tasks, including registry analysis and file system examination. Although these tools were originally developed for Windows, you can also run them on a Linux, as I will show in this blog post.


To do so, I will show how to :

  1. install Wine
  2. install .NET 6
  3. download and run the tools


To run the tools, you will need a recent version of the wine emulator. So you must install a recent version from the repository of wine.

Enable 32 bit architecture, as it is used by some wine components:

sudo dpkg --add-architecture i386

Import the signing key:

sudo mkdir -pm755 /etc/apt/keyrings
sudo wget -O /etc/apt/keyrings/winehq-archive.key

Check your Ubuntu release and codename:

cat /etc/os-release


Depending on your Ubuntu codename, add the appropriate repository…

For noble:

sudo wget -NP /etc/apt/sources.list.d/

For jammy:

sudo wget -NP /etc/apt/sources.list.d/

For focal:

sudo wget -NP /etc/apt/sources.list.d/

Install wine:

sudo apt update
sudo apt install --install-recommends winehq-stable

For more details, see

.NET 6.0

The tools require the .NET framework version 6. You can download the framework from

Be sure to download the .NET Desktop Runtime for Windows


At the time of writing, the latest version is numbered is 6.0.32, so the file name is windowsdesktop-runtime-6.0.32-win-x64.exe. Yes, a .exe: you can double-click on the downloaded file and it will be executed (and installed) by wine.


Eric Zimmerman’s forensic tools

You can now download the tools from

Unlike Windows, there is no installer or updater for Linux. So you must download each tool individually. Each tool is a .zip file that you must extract. Once done you can run the tool with a double-click.


This blog post is licensed under CC BY-SA 4.0

This website uses cookies. More information about the use of cookies is available in the cookies policy.