V7.0 (Build 1005)
Latest release date:
10th October 2019
What's new for this release.

Professional edition: US$995.00

Professional Upgrade: US$590.00

Both editions includes 12 months of support and updates.

(See feature comparison for more information)

Windows Vista, Win 7, Win 8, Win 10, Server 2000, 2003, 2008, 2012, 2016, 2019. Available for both 32-bit and 64-bit platforms.

Minimum 1GB of RAM. (8GB+ recommended)
200MB of free disk space, or can be run from USB drive

Related free tools:
Volatility Workbench

PassMark OSForensicsOSForensics - Digital investigation

OSForensics allows you to identify suspicious files and activity with hash matching, drive signature comparisons, e-mails, memory and binary data.

It lets you extract forensic evidence from computers quickly with advanced file searching and indexing and enables this data to be managed effectively.

OSForensics - Main window OSForensics - Main window

Click the images to view screenshots.

New in V7

  • Ability to boot an image as a Virtual Machine from OSForensics.
  • Addition of System Resource Usage Monitor (SRUM) database scanning for User Activity collection
  • OCR (Optical character recognition) allows you to search for text within PDF files
  • New built in hash sets for: Keyloggers, VPN Software, Peer to Peer (P2P) software, Cryptocurrency
  • Support for importing Project VIC hash sets


Discover Forensic Evidence Faster

Identify Suspicious Files and Activity

  • Verify and match files with MD5, SHA-1 and SHA-256 hashes
  • Find misnamed files where the contents don't match their extension
  • Create and compare drive signatures to identify differences
  • Timeline viewer provides a visual representation of system activity over time
  • File viewer that can display streams, hex, text, images and meta data
  • Email viewer that can display messages directly from the archive
  • Registry viewer to allow easy access to Windows registry hive files
  • File system browser for explorer-like navigation of supported file systems on physical drives, volumes and images
  • Raw disk viewer to navigate and search through the raw disk bytes on physical drives, volumes and images
  • Web browser to browse and capture online content for offline evidence management
  • ThumbCache viewer to browse the Windows thumbnail cache database for evidence of images/files that may have once been in the system
  • SQLite database browser to view the and analyze the contents of SQLite database files
  • ESEDB viewer to view and analyze the contents of ESE DB (.edb) database files, a common storage format used by various Microsoft applications
  • Prefetch viewer to identify the time and frequency of applications that been running on the system, and thus recorded by the O/S's Prefetcher
  • Plist viewer to view the contents of Plist files commonly used by MacOS, OSX, and iOS to store settings
  • $UsnJrnl viewer to view the entries stored in the USN Journal which is used by NTFS to track changes to the volume

Manage Your Digital Investigation

Professional and Bootable Editions

The professional and bootable editions of OSForensics have many features not available in the free edition, including;

  • Import and export of hash sets
  • Customizable system information gathering
  • No limits on the amount of cases being managed through OSForensics
  • Restoration of multiple deleted files in one operation
  • List and search for alternate file streams
  • Sort image files by colour
  • Disk indexing and searching not restricted to a fixed number of files
  • No watermark on web captures
  • Multi-core acceleration for file decryption
  • Customizable System Information Gathering
  • View NTFS directory $I30 entries to identify potential hidden/deleted files

The bootable edition contains all the professional features plus the ability to be run on systems without a valid operating system. See the full comparison list between the editions.

Volume & Site Licensing Pricing

We offer discounts for volume licensing and site licenses.

Quantity Price Per License
1-4 OSForensics Licenses Request a Quote
5-10 OSForensics Licenses Request a Quote
11+ OSForensics Licenses Request a Quote
OSForensics Site License Request a Quote

For further information on multi-user licenses and site licenses, please read our FAQ.

Upgrading to Version 7

To upgrade any version of OSForensics to OSForensics V7, please visit our Upgrade order page for details.
Free upgrades are available for all existing users with active support. This includes users who purchased on or after 31st July 2018.

Download Add to cart

Conference banner