
GITNUXSOFTWARE ADVICE
Legal Justice SystemTop 10 Best Forensic Analysis Software of 2026
Ranked roundup of forensic analysis software tools with FTK, EnCase, and Magnet AXIOM, plus X-Ways Forensics and SIFT Workstation.
How we ranked these tools
Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.
Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.
AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.
Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.
Score: Features 40% · Ease 30% · Value 30%
Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy
X-Ways Forensics is the strongest fit when Windows-centric cases need fast triage, timeline correlation, and artifact extraction from images, while Magnet AXIOM suits teams that want quicker, repeatable artifact analysis across many case files and devices when you can’t standardize just one workflow.
Editor’s top 3 picks
Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.
X-Ways Forensics
Timeline reconstruction links heterogeneous evidence sources into a single sortable event view with consistent provenance handling.
Built for fits when Windows-centric cases need fast triage, timeline correlation, and artifact extraction from images..
Magnet AXIOM
Editor pickCase reporting that ties parsed artifacts to timelines and entity pivots during analysis.
Built for fits when investigators need fast, repeatable artifact analysis across many case files and devices..
SIFT Workstation
Editor pickCurated SIFT Workstation image standardizes investigator workflows with bundled acquisition and analysis utilities.
Built for fits when labs need consistent triage and artifact extraction across many cases with shared tooling..
Related reading
Comparison Table
Forensic analysis software matters because evidence moves from acquisition into searchable data models, where investigators need fast indexing, repeatable workflows, and auditable handling across disk, mobile, memory, and network sources. This ranked list targets analysts and technical evaluators who must compare FTK, EnCase, and Magnet AXIOM on practical throughput, configuration depth, and workflow automation for casework under strict evidentiary standards.
X-Ways Forensics
enterpriseAdvanced computer forensic examination tool for disk imaging, data recovery, and analysis.
Timeline reconstruction links heterogeneous evidence sources into a single sortable event view with consistent provenance handling.
X-Ways Forensics is built around an investigator workflow that starts with evidence import and hash verification, then moves into artifact-focused views for registry hive parsing and file system structures. Timeline reconstruction groups events across multiple sources and reduces manual correlation work during triage. Keyword indexing speeds up review of extracted documents and textual artifacts. Hash verification and evidence case handling support evidence chain of custody practices during repeated analysis steps.
A tradeoff is that the strongest workflows follow Windows forensic artifacts, which can reduce efficiency when investigations center on highly custom mobile extraction or hardware-level acquisition. X-Ways Forensics fits best for teams that already have evidence images and need fast, repeatable artifact extraction and cross-view correlation for incident response and case work.
- +Hash verification and consistent case workflows reduce evidence handling mistakes
- +Timeline reconstruction correlates events across multiple extracted sources
- +Fast keyword indexing accelerates document review during triage
- +Windows registry hive parsing supports deep artifact inspection
- –Best fit skews toward Windows artifact analysis workflows
- –Advanced automation and API-style integration are limited for external orchestrators
- –Some acquisition workflows depend on external tools and image readiness
Digital forensic responders
Incident triage on image sets
Shortened review time
Forensic investigators
Registry-centric Windows investigations
Faster hypothesis validation
Show 1 more scenario
Case management teams
Repeatable evidence handling
More consistent documentation
Run hash verification and maintain structured case workflows through evidence import.
Best for: Fits when Windows-centric cases need fast triage, timeline correlation, and artifact extraction from images.
More related reading
Magnet AXIOM
enterpriseDigital investigation platform for computer, mobile, and cloud evidence analysis.
Case reporting that ties parsed artifacts to timelines and entity pivots during analysis.
Magnet AXIOM is a case analysis tool that consumes evidence images and extracted data, then produces artifact views like file system, application data, and communications artifacts. The analysis pipeline focuses on parsing and indexing so investigators can pivot from one artifact type to related entities without manually running every decoding step. Report building is designed around investigator outputs, which reduces the friction between analysis and documentation. For teams that handle high volumes of similar matters, AXIOM’s automation and repeatability fit triage collection and structured review workflows.
A key tradeoff is that AXIOM’s analysis depth depends on the quality and completeness of the input acquisition, so partial captures can reduce artifact coverage. It works best when evidence is already acquired with consistent methods and when the case team wants fast, consistent artifact extraction across many files and devices. For live response efforts, it requires a separate acquisition step before AXIOM can parse the artifacts and generate case outputs.
- +Strong artifact parsing for communications and application data
- +Repeatable case workflows reduce variation across analyst reviews
- +Correlation views support faster pivoting between related evidence
- +Investigator-oriented reporting outputs evidence summaries quickly
- –Artifact coverage drops when acquisitions are incomplete or inconsistent
- –Some advanced investigations require deeper analyst work outside core views
- –Complex cases can require careful evidence mapping to avoid missed links
Digital forensic teams
Large case backlogs with consistent parsing
Faster case turnaround
Mobile evidence reviewers
Structured analysis of mobile app data
Clear message and app timelines
Show 2 more scenarios
Litigation support staff
Report-ready evidence summaries
More consistent reporting
Generates documentation from analysis outputs to reduce manual reformatting work.
Incident response analysts
Post-acquisition triage collection review
Reduced analyst search time
Indexes acquired data so investigators can locate relevant artifacts without reprocessing everything.
Best for: Fits when investigators need fast, repeatable artifact analysis across many case files and devices.
SIFT Workstation
enterpriseLinux-based open-source forensic virtual appliance for evidence analysis.
Curated SIFT Workstation image standardizes investigator workflows with bundled acquisition and analysis utilities.
SIFT Workstation centers on a curated Linux-based environment that bundles acquisition and analysis utilities for handling logical and physical evidence workflows. Investigators can move from triage collection into file-system examination, artifact extraction, and indexing without switching machines or environments. Hash verification and evidence collection steps fit into repeatable workflows that keep examiner actions consistent across teams.
A key tradeoff is that the environment is opinionated and case workflows that depend on a specific Windows-only viewer may require external tooling or evidence re-export. It fits well for high-throughput incident response labs that run the same triage and artifact extraction steps across many endpoints.
- +Preconfigured workstation image reduces per-case setup variance
- +Scripting-friendly environment for repeatable triage and extraction steps
- +Integrated evidence workflow avoids tool switching during analysis
- +Linux-based toolchain fits automation and headless processing patterns
- –Windows-only examination workflows often require alternate viewers
- –Versioned tool bundle can lag behind specialized updates for edge cases
- –Remote lab usage requires careful storage planning for large images
- –Extensibility still depends on adding and maintaining extra packages
Incident response teams
Rapid endpoint triage and indexing
Faster triage results
Forensic labs
Repeatable disk and file examination
More consistent findings
Show 1 more scenario
Train and certify programs
Hands-on training lab setup
Lower training admin effort
Deploys the same tool bundle to students for stable, comparable exercises and labs.
Best for: Fits when labs need consistent triage and artifact extraction across many cases with shared tooling.
Autopsy
enterpriseOpen-source digital forensics platform for analyzing disk images and mobile devices.
Analysis modules built on the Autopsy platform allow targeted parsers and extractors tied directly into the case workflow.
Autopsy is an open source forensic analysis application built on the Sleuth Kit and focusing on investigator-driven workflows. It supports disk imaging ingestion, hash verification during import, and file system and artifact processing to produce timelines and search results.
Its extensibility model lets investigators add analysis modules for new data sources and parsing logic, which matters when cases require repeatable custom checks. For evidence handling workflows, it supports hash-based import tracking and report generation suited to repeatable examinations.
- +Tight Sleuth Kit integration for file system and artifact parsing
- +Extensibility via custom modules for case-specific processing logic
- +Hash-based import support improves integrity checks during ingestion
- +Timeline and search views help drive repeatable triage workflows
- –User management and audit controls are not as governance-oriented as enterprise tools
- –Some advanced workflows rely on manual configuration and module selection
- –Nonstandard sources often require custom ingest or parsing modules
- –Large case datasets can feel slow without careful indexing and storage planning
Best for: Fits when investigators need extensible forensic parsing with repeatable triage, not a closed commercial workflow.
FTK Forensic Toolkit
enterpriseCourt-validated digital investigation platform for processing, searching, and analyzing electronic evidence.
Integrated content indexing plus keyword-driven case navigation tied to exportable evidence reports.
FTK Forensic Toolkit ingests disk images and drives guided evidence workflows through indexing, content extraction, and case reporting. It includes hash verification, metadata extraction, and keyword-searchable views over multiple file system artifacts.
FTK focuses on repeatable triage collection and fast navigation across large evidence sets, with options to export results for handoff to analysis teams. When paired with evidence format handling and conversion workflows, it supports both logical and physical image analysis in the same case.
- +Fast keyword indexing across large evidence sets for triage speed
- +Hash verification and evidence integrity checks during import
- +Structured artifact views for registry, file metadata, and case reporting
- +Strong export paths for reports and evidence handoff
- –Automation depth and API coverage are limited versus script-first ecosystems
- –Deep multi-format ingestion can require careful evidence prep
- –Timeline workflows depend on artifact availability and indexing quality
- –Live acquisition workflows are not the primary strength
Best for: Fits when incident responders need repeatable indexing and artifact review for disk images.
EnCase Forensic
enterpriseIndustry-standard forensic acquisition and analysis tool for computers and mobile devices.
Keyword indexing tied to structured evidence views for fast review of large collections without losing provenance.
EnCase Forensic from OpenText targets full-scope digital investigations where examiners need repeatable acquisition, deep filesystem parsing, and reportable evidence views. It supports logical and physical image handling, hash verification workflows, and artifact extraction across common Windows structures without forcing separate tools for core triage.
Keyword-driven review and timeline-style outputs fit case teams that process many related artifacts from the same evidence set. Automation for batch processing and extensibility for custom examination logic help teams standardize work across examiners.
- +Evidence-centric workflow links acquisition, verification, and review in one exam timeline
- +Strong support for Windows artifacts through structured parsing of host metadata
- +Keyword indexing accelerates search across large evidence sets and logical views
- +Extensibility supports custom examination steps for repeatable casework
- –Junctions and edge-case containers can increase time spent validating parse results
- –Advanced automation needs careful configuration to avoid inconsistent batch outputs
- –Scales best with established examiner training and workspace conventions
- –Some mobile and specialty sources depend on dedicated acquisition paths
Best for: Fits when case teams need repeatable evidence workflows with standardized review output across many similar investigations.
Cellebrite UFED
enterpriseMobile forensic extraction and analysis platform for locked and encrypted devices.
Mobile extraction workflows that adapt to device state and enable consistent, exportable evidence collections for case review.
Cellebrite UFED focuses on mobile-first forensic acquisition, including targeted extractions from many smartphone and tablet models without relying only on standard disk imaging workflows. UFED builds investigations around exportable evidence collections and repeatable processing steps, which helps teams move from acquisition to review and report building.
The workflow commonly pairs with companion tools in Cellebrite ecosystems for analysis and case management across device and collection types. For teams that frequently handle incidents involving handsets, UFED’s extraction breadth and operator-guided process design reduce turnaround time versus manual, per-artifact approaches.
- +Device acquisition workflow tailored for smartphones and tablets
- +Operator-guided steps support consistent evidence collection across cases
- +Evidence outputs are designed for downstream review and reporting
- +Broad model coverage for logical mobile extractions
- –Best fit is mobile extraction, not general endpoint disk imaging
- –Cabling and device state handling can slow acquisition sessions
- –Advanced outcomes often depend on correct toolchain provisioning
- –Large collections can require extra time to organize into review-ready views
Best for: Fits when handset-heavy incident response teams need repeatable mobile extractions for evidence packages and reports.
Volatility
enterpriseOpen-source memory forensics framework for extracting artifacts from RAM captures.
Rapid artifact extraction via OS- and version-specific memory parsing plugins for process, network, and registry-resident structures.
Volatility couples a memory forensics engine with a structured workflow for extracting artifacts from volatile and crash images. It focuses on analyst-driven parsing of in-memory objects such as process lists, registry-resident data, and file system remnants where available.
Output can be adapted for repeatable triage through exportable result formats and automation-friendly command execution. The practical differentiator is the breadth of image parsers and plugins that target specific memory layouts instead of only presenting a generic viewer.
- +Plugin ecosystem targets specific operating system memory structures and artifacts
- +Consistent CLI workflow supports scripted triage across multiple cases
- +Deterministic parsing output supports repeatable extraction and validation
- +Rich support for crash and memory-image artifacts beyond basic process viewing
- –Plugin selection and volatility profile matching can fail without careful setup
- –Some advanced workflows require multiple passes and manual interpretation
- –Not a full file-system forensics suite for non-memory evidence sets
- –Large images can reduce throughput and increase extraction latency
Best for: Fits when incident response teams need fast, repeatable volatile memory artifact extraction and triage evidence.
Wireshark
enterpriseOpen-source network protocol analyzer for capturing and inspecting packet data.
Lua scripting over packet dissector fields enables custom automated classification during offline replay of capture files.
Wireshark captures and inspects network traffic at packet level for forensic workflows that need protocol-aware visibility and reproducible analysis. It supports offline analysis of capture files with filtering, stream reconstruction, and deep inspection of common protocols across TCP, UDP, and many higher-layer standards.
Wireshark exports structured results via dissector fields and supports scripting with Lua for repeatable collection and triage steps. Wireshark is distinct because its protocol dissectors drive the analysis, not just raw byte viewing.
- +Protocol dissectors drive targeted inspection across many capture formats
- +Powerful display filters and follow stream for faster triage
- +Export of dissector fields supports repeatable reporting workflows
- +Lua scripting enables automated packet classification and extraction
- –No built-in end-to-end evidence chain of custody tracking
- –Live capture increases handling risk without disciplined lab separation
- –High-volume analysis can strain throughput on large captures
- –Forensic timelines require extra correlation and external tooling
Best for: Fits when network-focused investigations need repeatable packet-level inspection and protocol-aware exports.
Foremost
enterpriseConsole-based file carving tool for recovering files based on headers and footers.
Signature rule customization and predictable carving output without a full forensic interface.
Foremost is distinct because it performs signature-based file carving with a minimal workflow and configurable rules.
It is commonly used to recover files from raw disk or image data when file system metadata is unreliable.
Foremost outputs carved files into a local directory layout that supports manual inspection and later correlation to other artifacts.
Evidence chain of custody, acquisition integrity, and hash verification must be handled by separate acquisition tooling and workflow controls.
- +Signature-based file carving works even when file systems are damaged
- +Simple configuration model makes repeat runs predictable across cases
- +Works on logical image files and raw disk data without special extractors
- +Output directory structure supports quick triage of carved results
- –Carving quality drops when signatures overlap or data is fragmented
- –No built-in evidence chain of custody or audit log for case governance
- –Does not parse complex structures like registry hive or MFT semantics
- –Requires external tooling for hash verification and acquisition integrity
Best for: Fits when analysts need fast signature-based file carving from images during triage.
Conclusion
After evaluating 10 legal justice system, X-Ways Forensics stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.
Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.
How to Choose the Right forensic analysis software
Forensic analysis software supports investigator workflows that range from disk and logical image review to artifact parsing, memory triage, and report generation across many evidence sets. This guide focuses on X-Ways Forensics, Magnet AXIOM, FTK Forensic Toolkit, EnCase Forensic, Autopsy, SIFT Workstation, Cellebrite UFED, Volatility, Wireshark, and Foremost.
The comparison emphasizes how each tool handles evidence workflows under repeatable review steps, with special attention to timeline reconstruction, evidence-centric indexing, and mobile or volatile acquisition paths. X-Ways Forensics is centered for Windows image triage and cross-source timeline correlation, while Magnet AXIOM is centered for case reporting that ties parsed artifacts to timelines and entity pivots.
Forensic analysis software for evidence-based artifact parsing, indexing, and governed case workflows
Forensic analysis software ingests logical images, physical images, and capture artifacts to extract file system structures, application artifacts, and memory or network evidence into analyst-facing views. It typically pairs verification steps like hash checking with case workflows that preserve provenance from import through export.
X-Ways Forensics highlights timeline reconstruction that links heterogeneous evidence sources into a single sortable event view with consistent provenance handling. EnCase Forensic emphasizes keyword indexing tied to structured evidence views so teams can run repeatable evidence workflows across large collections. Magnet AXIOM adds case reporting that ties parsed artifacts to timelines and entity pivots during analysis, which supports faster analyst cross-referencing across many case files.
Evaluation criteria for forensic analysis software case workflows
Forensic analysis software must turn evidence ingestion into repeatable analyst steps, with verification and provenance carried from import to export. The tools below differ most in how they index extracted artifacts, how they connect artifacts to timelines, and how they support structured case review across many evidence sets.
X-Ways Forensics prioritizes timeline reconstruction that links heterogeneous evidence sources into one sortable event view with consistent provenance handling. Magnet AXIOM emphasizes case reporting that ties parsed artifacts to timelines and entity pivots during analysis, which drives faster cross-referencing when many items must be reviewed in a consistent order.
Timeline reconstruction and event correlation
X-Ways Forensics links heterogeneous evidence sources into a single sortable event view with consistent provenance handling. Magnet AXIOM ties parsed artifacts to timelines and entity pivots during analysis for repeatable case reporting.
Evidence-centric indexing and review navigation
FTK Forensic Toolkit builds integrated content indexing plus keyword-driven case navigation tied to exportable evidence reports. EnCase Forensic ties keyword indexing to structured evidence views to keep provenance attached to the review timeline.
Governed workflow controls versus analyst workflow extensibility
Autopsy is built for extensible parsing with custom modules tied into the case workflow. X-Ways Forensics supports consistent case workflows with hash verification and timeline-centered evidence handling.
Acquisition-aligned workflows for specific evidence types
Cellebrite UFED focuses on mobile extraction workflows that adapt to device state and produce consistent exportable evidence collections. Volatility uses an OS- and version-specific plugin ecosystem with a scripted CLI workflow for rapid volatile memory artifact extraction.
Extensibility and script-driven repeatability for triage
Autopsy supports targeted parser and extractor modules directly inside the case workflow. SIFT Workstation delivers a curated image that standardizes triage and artifact extraction with bundled utilities that are scripting-friendly.
Decision framework for selecting forensic analysis software by workflow fit
Selection starts with how evidence review must be structured during triage and deeper analysis. Tools that emphasize timeline correlation and evidence provenance reduce the chance of analyst drift when multiple evidence sources must be compared in one review sequence.
Then the decision should map to the evidence type that dominates case volume. Mobile teams should align to Cellebrite UFED acquisition workflows, while incident response teams relying on volatile memory extraction should align to Volatility plugin coverage and CLI-driven repeatability.
Choose a timeline-first workflow when multiple evidence sources must be correlated
Pick X-Ways Forensics when heterogeneous evidence must appear in one sortable event view with consistent provenance handling. Pick Magnet AXIOM when the analysis output must repeatedly connect parsed artifacts to timelines and entity pivots for case reporting.
Choose indexing and keyword navigation when teams need repeatable evidence review outputs
Pick FTK Forensic Toolkit when fast keyword indexing across large evidence sets drives triage speed and exportable evidence reports must be generated. Pick EnCase Forensic when structured evidence views keep provenance attached to the exam timeline and keyword indexing must stay consistent across similar investigations.
Choose extensibility when parsing needs vary by case and lab standards
Pick Autopsy when custom extractors must plug directly into the case workflow and parsing behavior must be adapted per investigation type. Pick X-Ways Forensics when evidence handling mistakes must be reduced through hash verification and consistent case workflows during import and review.
Choose a curated workstation image when lab consistency matters more than per-tool specialization
Pick SIFT Workstation when labs need consistent triage and artifact extraction across many cases with shared tooling. Use FTK Forensic Toolkit instead when repeatable content indexing and keyword-driven review navigation tied to exportable evidence reports is the primary driver.
Fork by evidence acquisition shape: mobile versus volatile memory
Pick Cellebrite UFED when case work depends on device-state-aware mobile extraction workflows that produce consistent exportable evidence packages. Pick Volatility when volatile memory triage must stay repeatable via an OS- and version-specific plugin ecosystem with a scripted CLI.
Who should buy each forensic analysis software tool
The right tool depends on the evidence sources, the required analyst workflow, and the need for consistent outputs across case teams. Some options focus on timeline reconstruction and provenance handling, while others focus on indexing and evidence-centric navigation, and still others focus on specialized acquisition workflows for mobile or volatile memory.
Digital forensic examiners running Windows-centric image triage and timeline correlation
X-Ways Forensics fits when Windows artifact analysis needs fast triage and cross-source timeline correlation inside one review workflow.
Investigations teams that must produce repeatable artifact analysis reports across many case files
Magnet AXIOM fits when parsed artifacts must be tied to timelines and entity pivots so reports stay consistent between analysts and across case batches.
Incident response teams that standardize mobile evidence collection into exportable packages
Cellebrite UFED fits when smartphone and tablet evidence dominates and device acquisition workflows must guide consistent evidence collection.
Incident response teams performing volatile memory triage at scale using scripted steps
Volatility fits when OS- and version-specific memory parsing plugins must support rapid extraction with a consistent CLI workflow across many cases.
Labs that require extensible forensic parsing without locking into a closed commercial workflow
Autopsy fits when targeted parsers and extractors must be added as custom modules tied directly into the case workflow.
Common pitfalls when buying forensic analysis software
Misalignment between evidence type and tool workflow can waste analyst time and degrade review consistency. Another common failure is underestimating governance controls and audit-oriented workflow support when multiple analysts contribute to the same case record.
Selecting a general-purpose interface for specialized evidence without matching the workflow shape
Cellebrite UFED is best fit for mobile extraction workflows rather than general endpoint disk imaging, and Volatility is best fit for volatile memory artifact extraction rather than general disk image review.
Assuming deep automation and external orchestration are available in the core product
X-Ways Forensics shows limited advanced automation and API-style integration for external orchestrators, and FTK Forensic Toolkit limits automation depth and API coverage versus script-first ecosystems.
Ignoring index and review navigation behavior that controls evidence review consistency
EnCase Forensic and FTK Forensic Toolkit differ in how keyword indexing maps to structured evidence views and exportable evidence reports, so evidence sets should be validated for review speed under real case content.
Underestimating module and configuration overhead when extensibility is the core differentiator
Autopsy extensibility depends on manual configuration and module selection, and Volatility plugin selection can fail without careful volatility profile matching.
How We Selected and Ranked These Tools
We evaluated each tool by features, ease, and value using the scores provided for overall, features, ease, and value. Features carried the highest weight at 40 percent, while ease and value each carried 30 percent to reflect how quickly teams reach repeatable review steps.
X-Ways Forensics ranked highest because timeline reconstruction links heterogeneous evidence sources into a single sortable event view with consistent provenance handling, which directly reduces review inconsistency during case correlation. EnCase Forensic scored highly for evidence-centric structured review output via keyword indexing, while Magnet AXIOM scored highly for case reporting that ties parsed artifacts to timelines and entity pivots.
Frequently Asked Questions About forensic analysis software
How do X-Ways Forensics, EnCase Forensic, and FTK handle logical and physical evidence images in the same case workflow?
Which tool is better for timeline reconstruction when the evidence set includes heterogeneous artifacts and many related files?
What tradeoff appears when using an extensible module framework like Autopsy versus a guided indexing workflow like FTK?
How does Magnet AXIOM compare to X-Ways Forensics for correlating chat, message, and application-level artifacts during analysis?
When should a lab standardize tooling with SIFT Workstation instead of installing Autopsy or FTK on each workstation?
What breaks if evidence chain of custody and integrity verification are handled outside the analysis tool?
How do Cellebrite UFED and Volatility differ when the target is mobile data versus volatile memory artifacts?
Which tool supports offline network packet analysis with protocol-aware fields and reproducible scripting for triage steps?
How do automation and extensibility differ between Magnet AXIOM, EnCase Forensic, and Autopsy?
What is the practical limitation of Foremost file carving compared with a full forensic interface like EnCase Forensic?
Tools reviewed
Primary sources checked during evaluation.
Referenced in the comparison table and product reviews above.
Keep exploring
Comparing two specific tools?
Software Alternatives
See head-to-head software comparisons with feature breakdowns, pricing, and our recommendation for each use case.
Explore software alternatives→In this category
Legal Justice System alternatives
See side-by-side comparisons of legal justice system tools and pick the right one for your stack.
Compare legal justice system tools→