Shop
OSForensics

OSForensics - Perpetual License with 12 months of support & updates

PassMark Software


1343.16 CHF
for EU and non-EU countries (except Switzerland) including 0% VAT

1451.95 CHF for Switzerland including 8.1% VAT


Free electronic delivery - 1-3 working days
Buy


Can't find what you are looking for? Contact us through chat widget, support form or email

OSForensics by PassMark Software is a powerful digital investigation tool designed to help forensic professionals uncover and analyze evidence efficiently.

  • Rapid File Search: Quickly locate files on Windows systems or forensic images, significantly outperforming standard search functionalities.
  • In-Depth File Content Search: Utilize an advanced indexing engine to perform fast searches within file contents, supporting a wide range of file types including Office documents, PDFs, and emails.
  • Email Analysis: Search and analyze email archives from various clients such as Outlook and Thunderbird, enabling efficient examination of communications.
  • Deleted File Recovery: Retrieve files that have been deleted or removed from the Recycle Bin, allowing access to data that users may have attempted to destroy.
  • User Activity Monitoring: Investigate recent user actions, including accessed websites, connected USB devices, and downloaded files, to build a comprehensive activity profile.
  • Password Recovery: Extract and recover passwords from web browsers, email clients, and Wi-Fi networks, facilitating access to protected information.
  • Hidden Disk Area Detection: Expose hidden areas on hard disks, such as HPA and DCO, which can be used to conceal data, ensuring no information remains hidden.
  • Volume Shadow Copy Access: Browse and analyze Volume Shadow Copies to view past versions of files and detect changes over time.
  • File Verification and Hash Matching: Verify file integrity using MD5, SHA-1, and SHA-256 hashes, and identify misnamed files where contents don't match their extensions.
  • Drive Signature Comparison: Create and compare drive signatures to detect differences and changes on a system, aiding in identifying unauthorized modifications.
  • Timeline Visualization: Utilize the Timeline Viewer to graphically represent file and system activity over time, helping to pinpoint significant events.
  • Comprehensive File Analysis Tools: Access a suite of tools including file viewers, email viewers, registry viewers, and raw disk viewers for thorough examination of various data types.
  • Case Management and Reporting: Organize evidence into secure case files and generate customizable reports to present findings effectively.
  • Drive Imaging and RAID Reconstruction: Create and restore disk images, and rebuild RAID arrays from individual disk images, ensuring data integrity during analysis.
  • Portable Operation: Run OSForensics from a USB drive, allowing investigations to be conducted directly on target systems without installation.