V2.2 (Build 1000)
Latest release date:
10th September 2013
What's new for this release.

Feature restricted edition: Free
Professional edition: US$499
(See feature comparison for more information)

Windows XP SP2, Vista, Win 7, Win 8, Server 2000, 2003, 2008, 2012. Available for both 32-bit and 64-bit platforms.

Minimum 1GB of RAM. (4GB+ recommended)
30MB of free disk space, or can be run from USB drive

Related free tools:

PassMark OSForensicsOSForensics - Digital investigation

OSForensics allows you to identify suspicious files and activity with hash matching, drive signature comparisons, e-mails, memory and binary data.

It lets you extract forensic evidence from computers quickly with advanced file searching and indexing and enables this data to be managed effectively.

OSForensics - Main window OSForensics - Main window

Click the images to view screenshots.


Discover Forensic Evidence Faster

Identify Suspicious Files and Activity

Manage Your Digital Investigation

Professional and Bootable Editions

The professional and bootable editions of OSForensics have many features not available in the free edition, including;

  • Import and export of hash sets
  • Customizable system information gathering
  • No limts on the amount of cases being managed through OSForensics
  • Restoration of multiple deleted files in one operation
  • List and search for alternate file streams
  • Disk indexing and searching not restricted to a fixed number of files

The bootable edition contains all the professional features plus the ability to be run on systems without a valid operating system. See the full comparison list between the editions.

Competitive Upgrade

If you have already purchased a competing forensics package, we want to offer you a competitive upgrade to make it an easier transition to OSForensics. You will receive a discount of 30% on your purchase of OSForensics if you qualify for the competitive upgrade. See here for more details.

Upgrade from Version 1 to Version 2

License keys issued for OSForensics version 1 contiue to be valid for version 2. Simply download the latest version and install it over the top of your current install.


Download Download OSForensics   |  
  |   Return to Products index