Complete suite for forensic investigation

Search files fast
Extensive file type support
Recover deleted evidence
Uncover user activity
Password recovery
Reveal hidden areas on a hard disk
Browse Volume Shadow copies
card-img

OSF provides one of the fastest and most powerful ways to locate files on a Windows computer or Forensic image.
Learn more

Search within the contents of files with the use of our acclaimed indexing engine providing industry leading relevance ranking, date range searching, exact phrase matching, “Google-like” context results and more.

Identify suspicious files and activity

Verify and match files
Identify changes
Timeline viewer
File analysis tools

Use OSF to confirm that files have not been corrupted or tampered with by comparing hash values or identify whether an unknown file belongs to a known set of files. Verify and match files with MD5, SHA-1 and SHA-256 hashes. Find misnamed files where the contents don't match their extension.
Learn more

card-img

Manage your digital investigation

Create case
Generate Report
Storage device management
Drive and system imaging
Audit trace
Take OSF with you
card-img

Organize all the evidence you have discovered into a single, cryptographically secure case file.
Learn more

Subscription, Perpetual and Bootable Editions

The Subscription, Perpetual and Bootable editions of OSForensics have many features not available in the Free edition, including;

  • Import and export of hash sets
  • Customizable system information gathering
  • No limits on the amount of cases being managed through OSForensics
  • Restoration of multiple deleted files in one operation
  • List and search for alternate file streams
  • Sort image files by colour
  • Disk indexing and searching not restricted to a fixed number of files
  • No watermark on web captures
  • Multi-core acceleration for file decryption
  • Customizable System Information Gathering
  • View NTFS directory $I30 entries to identify potential hidden/deleted files
  • Memory viewer and dumper - Kernel mode acquisition to bypass anti-dump tools

The bootable edition contains all the features plus the ability to be run on systems without a valid operating system. See the full comparison list between the editions.

card-img

Free Tools

The following collection of tools are provided as free downloads for use with OSForensics™.


OSFMount

OSFMount allows you to mount local disk image files in Windows as a physical disk or a logical drive letter.

OSFClone

OSFClone enables you to create or clone exact raw disk images quickly and independent of the installed operating system.

Volatility Workbench

Volatility Workbench is a graphical user interface (GUI) for the Volatility tool.

ImageUSB

ImageUSB is a free utility which lets you write an image concurrently to multiple USB Flash Drives.