Skip to content

OSForensics

Digital forensics and incident response toolkit from Australia's PassMark Software, used for disk imaging, file recovery, memory analysis and case management by investigators.

Visit Website ↗ + Add to Compare
45/100Emerging / Unranked

Overview

OSForensics is a digital forensics toolkit built by PassMark Software, a small Sydney-based company better known for its PerformanceTest and BurnInTest benchmarking tools. OSForensics packages the core tasks of a computer forensic investigation — disk imaging, deleted file recovery, password extraction, memory analysis, hash-based evidence matching, timeline reconstruction and case reporting — into a single Windows application covering Windows, Mac, Linux and Android artifacts.

Founded in 1998, PassMark Software has stayed small and self-funded, with roughly a dozen employees split between its Sydney head office and a California branch. OSForensics is sold and resold through forensics-focused distributors that cater specifically to law enforcement and government investigators, such as Digital Intelligence and H-11 Digital Forensics, which is one of the more concrete signals that the tool sees real use in actual investigations rather than just marketing claims.

Its main differentiator in a market that includes far more expensive suites like EnCase and FTK is price and accessibility: OSForensics gives smaller law enforcement units, corporate investigators and IT security teams a full-featured forensics toolkit without enterprise forensic software budgets. It hasn’t been independently lab-tested or benchmarked against those larger suites in any evaluation found during this research, so claims about its completeness and reliability rest mainly on longevity and reseller/practitioner adoption rather than third-party validation.

Innovation Matrix Assessment

Innovation Velocity 5/10

OSForensics has shipped a steady stream of version updates adding mobile (Android) and expanded file-system support over its product life, a reasonable pace for a small, self-funded team.

Operational Value 4/10

PassMark Software operates with roughly a dozen employees across two offices; that lean structure has sustained a niche forensics product for over a decade but limits capacity for large-scale enterprise support.

Market Momentum 4/10

No funding events or acquisitions found; growth signals are limited to continued distribution through law-enforcement-focused resellers rather than any publicly reported expansion metrics.

Category Disruption 4/10

Its main disruption is price and accessibility relative to enterprise forensic suites like EnCase and FTK, making forensic capability available to smaller units and teams, rather than introducing a fundamentally new investigative technique.

Real-World Efficacy 5/10

Distribution through law-enforcement-specialist resellers (Digital Intelligence, H-11 Digital Forensics) is a real, independently observable adoption signal, but no independent lab evaluation or benchmark against competing forensic suites was found.

Enduring Relevance 5/10

Digital forensics and incident-response evidence handling remain core security operations functions, though OSForensics serves a narrower, more specialized slice of that market than full incident-response platforms.

Why CISOs Should Care

Gives smaller security, IT and law-enforcement teams a full-featured, affordable forensics toolkit for internal investigations and incident response without committing to an enterprise forensic suite budget.

What Makes It Different

Bundles the full range of forensic tasks — imaging, recovery, memory analysis, hashing, timelining, reporting — into one lower-cost application rather than requiring multiple specialized tools.

The Matrix Verdict

45/100 — EMERGING / UNRANKED

A longstanding, affordable niche forensics tool with real practitioner adoption through specialist resellers, but limited independent validation and a very small team behind it.

Editorial Note: Claims vs. Verified Findings

PassMark's description of OSForensics as 'incredibly powerful, fast and reliable' is vendor language. Its distribution through law-enforcement-focused resellers such as Digital Intelligence and H-11 Digital Forensics is independently observable evidence of real-world use; no independent lab benchmark against competing forensic suites was found.

Sources