Manage your digital investigation.

Create a Case

Group all gathered evidence together into an OSF Case file for later use. All data is cryptographically hashed to prevent tampering.
More »

Create a Case

Generate a Report

Once created, case files can be exported into easily HTML and PDF readable reports summarizing the evidence found. Externally created reports can be added, and case narratives can be edited using the HTML editor.More »

Generate a Report

Storage Device Management

Manage your storage devices in a centralized manner for convenient access throughout OSForensics. More »

Storage Device Management

Drive Imaging

Create and restore disk images of evidence disks, to support forensics analysis without risking the integrity of the original data. More »

Drive Imaging

Rebuild RAID Arrays

Rebuild a complete RAID image from a set of RAID member disk images. More »

Rebuild RAID Arrays

Take OSForensics With You

OSForensics can be installed and run from a portable USB drive. Take the investigation straight to the target computer without risking the contamination of valuable forensic information. More »

Forensic software runs directly from USB drive

Imaging live systems

Take exact copies of the partitions or drives of an active system. Useful for live acquisitions while running OSForensics from your USB drive. You can also image a drive from a non-live system using our tool, OSFClone. More »

Disk imaging for live acquisitions

Maintain an audit trace

OSForensics can automatically maintain a secure audit trail of the exact activities carried out during the course of the investigation More »

Maintain an audit trail of your case activities

Support

Purchasing OSForensics includes business hours support. Contact options include phone, email or through our online forums.  More »

Support