• Home
  • Products
  • Training
  • Support
  • About Us
  • Forum
  • Sign In

Verify and Match Files

Discover
  • Find files faster
  • Search within files
  • Search for E-mails
  • Recover deleted files
  • Uncover User Activity
  • Collect system information
  • Password recovery
  • Hidden Disk Areas - HPA/DCO
  • Volume Shadow Copy
  • Web Browser
Identify
  • Verify and match files
  • Find misnamed files
  • Compare drive signatures
  • Timeline viewer
  • File viewer
  • Memory viewer
  • Binary String Extraction
  • Email viewer
  • Registry viewer
  • File system browser
  • Raw disk viewer
  • Thumbnail cache viewer
  • SQLite database browser
  • ESE database browser
  • Prefetch viewer
  • $UsnJrnl viewer
  • Plist viewer
  • Event Log Viewer
  • Web Server Log Viewer
Manage
  • Case management
  • Generate reports
  • Storage device management
  • Drive Imaging
  • Cloud Drive Imaging
  • Cloud Account Imaging
  • Rebuild RAID arrays
  • Portability
  • Secure case logging
  • Support

Create and verify hash values for files and disk volumes.OSForensics™ makes use of number of advanced hashing algorithms to create a unique, digital fingerprint that can be used to identify a file.
Use OSForensics to confirm that files have not been corrupted or tampered with by comparing hash values, or identify whether an unknown file belongs to a known set of files.

Hash Set Lookup

OSForensics makes use of hash sets to quickly identify known safe or known suspected files to reduce the need for further time-consuming analysis. A hash set consists of a collection of hash values of these files in order to search a storage media for particular files of interest. In particular, files that are known to be safe or trusted can be eliminated from file searches. Hash sets can also be used to identify the presence of malicious, contraband, or incriminating files such as bootleg software, pornography, viruses and evidence files.

Use hash sets to quickly identify known files

Create and Verify Hash Values

Create a unique, digital identifier for a file or disk volume by calculating its hash value using the Verify/Create Hash module in OSForensics. Choose from a number of cryptographic algorithms to create a hash, such as SHA-1, MD5 and SHA-256. Hash values uniquely identify the contents of a file and can be used to discover other files with the same content, regardless of differing file name or file extension.

The Verify/Create Hash module uses cryptographic algorithms to create hash values.

For disk volumes, a single hash value is created which describes the content of files, directory structures as well as unallocated space on the specified volume. Verify that a disk volume has not been corrupted or tampered with by comparing the new hash value with the original and expected hash value, for example, when verifying exact disk duplicates created by the free OSForensics disk cloning tool, OSFClone.

Home
Discover Identify Manage
Contact Us Legal Disclaimer Privacy Policy
Products
OSForensics OSForensics Bootable (USB Flash Drive) Rainbow Tables - 3TB hard disk
Training
Online Training Course Certification Exam - Online Triage Exam - Online Face-to-Face Classes 2026 Events Calendar
Support
Video Demonstrations FAQs and Tutorials OSForensics Forums Australian Head Office North American Branch

Copyright © 2025 PassMark™ Software