
OSForensics
eDiscovery software
Legal software
- Features
- Ease of use
- Ease of management
- Quality of support
- Affordability
- Market presence
Take the quiz to check if OSForensics and its alternatives fit your requirements.
$95.00 per user per month
Small
Medium
Large
- Information technology and software
- Construction
- Real estate and property management
What is OSForensics
OSForensics is a Windows-based digital forensics and incident response tool used to acquire, search, and analyze data from computers and storage media. It supports use cases such as internal investigations, litigation support, and security incident triage by enabling keyword searches, artifact review, and evidence collection. The product is typically used by forensic examiners, IT/security teams, and consultants who need workstation-level analysis rather than a full end-to-end eDiscovery review platform.
Broad endpoint artifact collection
OSForensics includes capabilities to collect and analyze common workstation artifacts such as files, browser history, email-related items, and system activity traces. It supports disk imaging and analysis workflows that are relevant for investigations where the source is a specific machine or drive. This makes it suitable for early case assessment and targeted evidence gathering before data is moved into downstream review processes.
Fast local indexing and search
The tool provides local indexing and keyword search across files and artifacts on a computer or mounted image. This can speed up triage when investigators need to locate relevant items quickly without standing up a separate review environment. It is most effective for single-machine or small-scope collections where local processing is practical.
Forensic-focused utilities included
OSForensics bundles multiple forensic utilities (for example, file viewer capabilities, hash-based identification, and artifact parsing) in one desktop application. This reduces the need to switch between separate tools for common investigative steps. The integrated approach is useful for practitioners who want a single interface for acquisition, analysis, and reporting on endpoint evidence.
Not a full eDiscovery platform
OSForensics focuses on endpoint forensics and does not provide the end-to-end eDiscovery workflow typically needed for large matters. Capabilities such as large-scale processing, hosted document review, advanced analytics, and production management are generally outside its core scope. Organizations often need additional systems for multi-custodian review and legal hold-to-production workflows.
Limited collaboration and governance
As a primarily desktop-oriented tool, OSForensics is less suited to multi-user collaboration, role-based review workflows, and centralized audit controls expected in enterprise legal operations. Sharing work product typically requires exporting reports or evidence sets rather than working in a shared review workspace. This can add operational overhead when multiple stakeholders must review the same corpus.
Windows-centric deployment model
OSForensics is designed for Windows environments, which can be limiting for teams that need native tooling across macOS and Linux endpoints. Cross-platform collections may require alternative acquisition methods or additional tools. This can complicate standardization for organizations with heterogeneous device fleets.
Plan & Pricing
| Plan | Price | Key features & notes |
|---|---|---|
| Trial Edition | $0 (30-day trial) | Feature-limited trial; stops working after 30 days. |
| Subscription | $95.00 per user/month (or $945.00 per user/year) | Continual access to major/minor updates and priority support; auto-renewal if paying by credit card. |
| Perpetual (12 months support) | $1,680.00 per user (includes 12 months support & updates) | Non-expiring license; includes 12 months of support/maintenance; no auto-renewal. |
| Perpetual (36 months support) | $3,675.00 per user (includes 36 months support & updates) | Non-expiring license; includes 36 months of support/maintenance. |
| Site License | Enquire (tiered pricing per estimated users) | Coverage for unlimited users within a single organization/country; contact sales for tiers and pricing. |
Seller details
PassMark Software Pty Ltd
Sydney, NSW, Australia
1998
Private
https://www.osforensics.com/
https://www.linkedin.com/company/passmark-software/