-
Latest Version
OSForensics 11.1.1004 LATEST
-
Review by
-
Operating System
Windows 7 / Windows 8 / Windows 10 / Windows 11
-
User Rating
Click to vote -
Author / Product
-
Filename
osf.exe
-
MD5 Checksum
1e640e4ecbf4aca14f421fe736551e4a
Manage your digital investigation and create reports from collected forensic data. Enjoy!
OSForensics can index the content of a huge variety of file formats. This includes: DOC, DOCX, PDF, PPT, XLS, RTF, WPD, SWF, DJVU, JPG, GIF, PNG, TIFF, MP3, DWF, DOCX, PPTX, XLSX, MHT, ZIP, PST, MBOX, MSG, DBX, ZIP, ZIPX, RAR, ISO, TAR, 7z and more.
Recursive containers are also supported. So it is possible to correctly index a DOCX file attached to an E-mail in a PST file which is in turn compressed in a ZIPX file.
It provides one of the fastest and most powerful ways to locate files on a Windows computer. You can search by filename, size, creation and modified dates, and other criteria. Results are returned and made available in several different useful views. This includes the Timeline View which allows you to sift through the matches on a timeline, making evident the pattern of user activity on the machine.
The first stage in being able to search emails is to create an index of the archives in question. This can take some time but it is what allows for repeated fast searches later on. OS Forensics allows you to perform full-text searches within email archives used by many popular e-mail programs such as Microsoft Outlook, Mozilla Thunderbird, Outlook Express, and more.
OSForensics allows you to recover and search deleted files, even after they have been removed from the Recycle Bin. This allows you to review the files that the user may have attempted to destroy. Each deleted file found is displayed with a corresponding Quality indicator between 0-100. A value towards 100 means that the deleted file is largely intact, with only a few missing clusters of data.
OSForensics scans your system for evidence of recent activity, such as accessed websites, USB drives, wireless networks, recent downloads, website logins, and website passwords. This is especially useful for identifying trends and patterns of the user, and any material or accounts that have been accessed recently.
With the program, you can recover browser passwords from Chrome, Edge, IE, Firefox, and Opera. This can be done on the live machine or from an image of a hard drive. Data recovered include, the URL of the website (usually HTTPS), the login username, the site's password, the browser used to access the site & the Windows user name. Blacklisted URLs are also reported, showing the user has visited the site but elected not to store a password in the browser.
It can discover and expose the HPA and DCO hidden areas of a hard disk, which can be used for malicious intent including hiding illegal data. The Host Protected Area (HPA) and Device Configuration Overlay (DCO) are features for hiding sectors of a hard disk from being accessible to the end-user.
The app includes built-in support for accessing Volume Shadow Copies. Shadow copies provide a glimpse of the volume at a point in time in the past. This will allow for the discovery of changes to files and even view possible deleted files.
It provides a basic web viewer with the ability to load web pages from the web and save screen captures of web pages to the case.
The Web Browser can be optionally configured to capture the webpages from a user-specified list of URLs. In addition, the Web Browser can capture all or a subset of linked pages (up to a single level)
Features and Highlights
- Import and export of hash sets
- Customizable system information gathering
- No limits on the number of cases being managed through OSForensics
- Restoration of multiple deleted files in one operation
- List and search for alternate file streams
- Sort image files by color
- Disk indexing and searching not restricted to a fixed number of files
- No watermark on web captures
- Multi-core acceleration for file decryption
- Customizable System Information Gathering
- Find files faster, search by filename, size and time
- Search within file contents using the Zoom search engine
- Search through email archives from Outlook, ThunderBird, Mozilla and more
- Recover and search deleted files
- Uncover recent activity of website visits, downloads, and logins
- Collect detailed system information
- Password recovery from web browsers, decryption of office documents
- Discover and reveal hidden areas in your hard disk
- Browse Volume Shadow copies to see past versions of files
Email Viewer: Fixed crashes when using “Jump to message” and exporting PST to MSG.
Hash Sets: Fixed issues with saving active hash databases and displaying them properly; updated import behavior and database warnings; resolved problems with inactive states and disabled fields.
Manage Case: Now shows an error if an incorrect key/password is used when adding BDE volumes.
USB Write-Block: Restores settings on exit/case deletion, adds detailed status info, verifies write-block by writing log files, auto-hides results, and includes a new per-device verification button. Removed from customize workflow.
License Comparison
- Trial Edition offers a 30-day free trial with forum support only, no upgrades, and one install.
- Perpetual License never expires, includes major/minor upgrades during the support period, and provides support via phone, email, and forum.
- Subscription License is valid as long as the subscription is active and includes all upgrades and full support.
- Support for Perpetual and Subscription includes phone, email, and forum; Trial only includes forum.
- Installations for Perpetual and Subscription allow 2 machine installs (e.g., lab and laptop) + 1 USB install for the same user.
- Auto-Renewal is only available for Subscription plans via credit card.
Trial: Free.
Perpetual: $1599 (12-month support) or $3499 (36-month support).
Subscription: $89/month or $899/year.
How to Use
- Launch the software and choose your desired workspace
- Use "Start" panel to access main forensic tools
- Perform file system scans using the "File Search" tab
- Capture memory and drive images for evidence
- Analyze emails, web history, and system artifacts
- Use hash matching to compare known file signatures
- Recover deleted files and view system activity
- Generate detailed reports from investigation results
- Save or export reports for legal documentation
- OS: Windows 11, 10, 8, 7
- CPU: 1 GHz or faster processor
- RAM: Minimum 2 GB (4 GB or more recommended)
- Disk Space: 500 MB free space (more for data analysis)
- Display: 1024x768 resolution or higher
- Other: Administrator rights required for full access
- Comprehensive forensic analysis toolkit
- Fast and powerful file search engine
- Live memory and drive imaging support
- Supports hash matching and signature analysis
- Portable version available for field use
- Interface may feel outdated to some users
- Learning curve for beginners
- Some features locked in free version
- Limited cloud or remote investigation tools
- Requires admin rights for full functionality
What's new in this version:
Email Viewer:
- Fixed crash due to regression in "Jump to message" right-click option
- Fixed possible crash when exporting PST to MSG
Hash Sets:
- Fixed some active hash databases not being saved when reopening OSF
- Fixed Hash DB link not showing all active DBs being used in Lookup File in Hash Set window if DB names are long
- Removed checks for active database when importing, user selects database to import to during import process
- Fixed one database always being active on OSF reopen if all were set to inactive
- Updated all the warnings about no active databases to be consistent
- Fixed some fields not being disabled while creating new hash set
Manage Case:
- Changed to throw error if key/password was incorrect when adding BDE volumes to case
USB Write-Block:
- Restored USB write-block setting on OSF exit and case deletion
- Enhanced USB write-block verification: Creates 'OSForensics write-block check.txt' on the target drive, appends test logs if the file exists.
- Enhanced status bar with more detailed information.
- Added a button in the list view for per-device write-block verification
- Displayed write-block check results, auto-hiding after 5 seconds
- Removed USB Write-block from the customize workflow list
User Activity:
- Web History, Fixed possible crash accessing the URL records for browser history when parsing WebCacheV01.dat. The URL may be empty/null for some entries
OperaOpera 117.0 Build 5408.197 (64-bit)
PC RepairPC Repair Tool 2025
PhotoshopAdobe Photoshop CC 2025 26.5.0 (64-bit)
OKXOKX - Buy Bitcoin or Ethereum
iTop VPNiTop VPN 6.4.0 - Fast, Safe & Secure
Premiere ProAdobe Premiere Pro CC 2025 25.2.1
BlueStacksBlueStacks 10.42.50.1004
Hero WarsHero Wars - Online Action Game
SemrushSemrush - Keyword Research Tool
LockWiperiMyFone LockWiper (Android) 5.7.2
Comments and User Reviews