OSForensics by Passmark Software is a full-feature, complete digital investigative software application. OSForensics supports digital investigations from field triage through evidence acquisition, analysis, and reporting.

OSForensics provides powerful, easy-to-use features that:

Allow you to discover relevant data faster through high performance file searching & indexing

Identify evidence and suspicious activity through hash matching & signature analysis

Build custom reports, add narratives, and attach other tool reports to OSForensics reporting

Manage your case flow from start to finish!

The professional and bootable editions of OSForensics have many features, including;

  • Import and export of hash sets
  • Customizable system information gathering
  • No limits on the amount of cases being managed through OSForensics
  • Restoration of multiple deleted files in one operation
  • List and search for alternate file streams
  • Sort image files by color
  • Disk indexing and searching not restricted to a fixed number of files
  • No watermark on web captures
  • Multi-core acceleration for file decryption
  • Customizable System Information Gathering
  • View NTFS directory $I30 entries to identify potential hidden/deleted files
  • Memory viewer and dumper – Kernel mode acquisition to bypass anti-dump tools

OSForensics Software Perpetual License


OSForensics Software + 1 Year Subscription