Download

Download OSForensics 11.0

281.1 MB, Build 1015

Older Versions

We are no longer working on older versions of OSForensics, but you can download the older versions of OSForensics on our website. This is purely for supporting users of the previous versions.

We recommend upgrading to Version 11 where possible, as we have improved many aspects of OSForensics and have addressed many issues based on user feedback.

If you do not wish to upgrade to Version 11, you can download old software releases here.

Version Download Old Version
OSForensics v10.0.1016 Download
OSForensics v9.2.1000 Download
OSForensics v8.0.1008 Download

System requirements

Win 7, Win 8, Win 10, Win 11
Windows Server 2012, 2016, 2019, 2022
64-bit support, 32-bit deprecated
Minimum 2GB of RAM. (16GB+ recommended)
500MB of free disk space, or can be run from USB drive

More details on recommended system requirements.

Download Hash Sets

OSForensics allows you to use Hash Sets to quickly identify known safe files (such as operating system and program files) or known suspected files (such as viruses, trojans, hacker scripts) to reduce the need for further time-consuming analysis. You can download some sample hash sets below. They are individually zipped.

Hash sets Size Download
Windows 11 Home build 22000 (x64) hash set 23,199 KB Download
Windows 10 Home 21H1 build 19043 (x64) hash set 32,542 KB Download
Windows 8.1 Professional (x64) hash set 10,228 KB Download
Windows 8.1 (x64) hash set 10,232 KB Download
Windows 8 Professional (x64) hash set 9,785 KB Download
Windows 8 (x64) hash set 9,785 KB Download
Windows 7 Ultimate (32-bit) hash set 18,825 KB Download
Windows 7 Enterprise (x64) hash set 11,670 KB Download
Windows Vista Business (32-bit) hash set 8,475 KB Download
Windows Vista Business (x64) hash set 8,069 KB Download
Windows XP Professional SP3 (32-bit) hash set 1,889 KB Download
Windows XP Professional SP2 (x64) hash set 1,456 KB Download
Office 365 v1806 build:10228 (Win10) hash set 1,528 KB Download
Office 2007 Enterprise (Vista) hash set 1,313 KB Download
Office 2007 Enterprise (Win7) hash set 1,978 KB Download
Common Keyloggers hash set. Old set from 2010 124 KB Download
Common Keyloggers hash set on Win10 64bit, 2019
Already bundled with OSF V7
281 KB Download
Common Peer to Peer P2P tools hash set on Win10 64bit, 2019.
Already bundled with OSF V7
1177 КВ Download
Common Cryptocurrency tools hash set on Win10 64bit, 2019.
Already bundled with OSF V7
761 KB Download
Common VPN tools hash set on Win10 64bit, 2019.
Already bundled with OSF V7
761 KB Download
NSRL Hash Sets by NIST (Available upon request)
Pre-converted format compatible with OSForensics
Send Request

The hash sets can also be purchased as a complete set pre-loaded onto a hard disk.

Installing the Hash Sets

To install the hash sets, you must download the individual zip files (linked above), and unzip them into the OSForensics program data folder.

This would typically be the following folder (you may need to enable viewing of hidden directories to see it or enter it directly into the Explorer address bar):
C:\ProgramData\PassMark\OSForensics\hashSets

You will then need to restart OSForensics if you have it currently open. When you next start OSForensics, you should now find additional sets listed in the tree view under the "Hash Sets" module.

Download Rainbow Tables

OSForensics enables you to utilize Rainbow Tables to retrieve passwords given that you have the hash (encrypted text) of that password. The use of rainbow tables serve essentially as a time-memory trade off in the decryption of a hash. That is, they store precomputed password to hash pairs, so that instead of generating these pairs on the fly, you can just search for a hash in the table to recover the password corresponding to that hash. OSForensics can generate Rainbow Tables for different input parameters. Some example Rainbow Tables are available below for download. They are individually zipped. To install the Rainbow Tables for use with OSForensics, refer to the paragraph below. To use these rainbow tables for password retrieval, click the "Retrieve Password with Rainbow Table" tab in the Passwords module of OSForensics. You can also download and use Indexed Rainbow Tables from rainbowtables.com (use RTI1 files only) with OSForensics.

Hash sets Size Download
md5_loweralpha-numeric#1-7_0_72656x4797112_OSF 32.6 MB Download
lm_alpha-numeric#1-7_0_23680x23656320_OSF 172 MB Download
sha1_loweralpha-numeric#1-6_0_4235x3708576_OSF 20.4 MB Download

The rainbow tables can also be purchased as a set pre-loaded onto a hard disk.

Installing the Rainbow Tables

To install the Rainbow Tables, you must download the individual zip files (linked above), and unzip them into the RainbowTables folder located in the OSForensics program data folder.

This would typically be the following folder (you may need to enable viewing of hidden directories to see it or enter it directly into the Explorer address bar):
C:\ProgramData\PassMark\OSForensics\RainbowTables

If you already have OSForensics open, then you may need to click the "Refresh" button under the rainbow tables display window to view the rainbow table/s you have added.