Download OSForensics 8.0.1000 (32 & 64 Bit)

OSForensics 8.0.1000 (32 & 64 Bit)

OSForensics 8.0.1000 (32 & 64 Bit)
OSForensics 8.0.1000 (32 & 64 Bit)


Digital investigations for a new era
For Windows
Identify suspicious files and activity
Extract evidence from computers quickly
Manage your investigation

The professional and bootable editions of OSForensics have many features not available in the free edition, including;

Import and export of hash sets
Customizable system information gathering
No limits on the amount of cases being managed through OSForensics
Restoration of multiple deleted files in one operation
List and search for alternate file streams
Sort image files by colour
Disk indexing and searching not restricted to a fixed number of files
No watermark on web captures
Multi-core acceleration for file decryption
Customizable System Information Gathering
View NTFS directory $I30 entries to identify potential hidden/deleted files

OSForensics™ helps you to organize all the evidence you have discovered into a single, cyptographically-secure case file. Add evidence and results to your case file for future analysis and have confidence that your case file has not been tampered with.

Case Management
Cases enable you to aggregate and organize results and case items from OSForensics' other discovery and idenfitication functions, such as File Search, File Mismatch Search, User Activity, Deleted Files and more. Once a case file has been created or opened, case items such as lists and files can be directly opened or deleted by the investigator for fast access.

When creating a case, OSForensics lets you enter in custom fields, load templates, and use the HTML editor to write up a case narrative.

Configure and add items to the current case quickly and easily. Edit case details, generate reports, generate reports, add external reports, add evidence photos, and add devices all from within the case management tab.

OSForensics™ provides one of the fastest and most powerful ways to locate files on a Windows computer. You can search by filename, size, creation and modified dates, and other criteria.

Results are returned and made available in several different useful views. This includes the Timeline View which allows you to sift through the matches on a timeline, making evident the pattern of user activity on the machine.

How fast?

OSForensics file search is many times faster than the search built into Windows. And unlike Windows which will often omit and miss files, you can be sure that OSForensics will find every file on your disk.

Search contents of files

OSForensics can also search the content of files and return results almost instantaneously after indexing. It is able to search within most common file formats and it is powered by Wrensoft's robustly accurate Zoom Search Engine.

Timeline View

Timeline view is an interactive bar graph that provides you with a visual view of the distribution of files with respect to file creation dates.