OSForensics
Digital forensics and incident response toolkit from Australia's PassMark Software, used for disk imaging, file recovery, memory analysis and case management by investigators.
Visit Website ↗ + Add to CompareOverview
OSForensics is a digital forensics toolkit built by PassMark Software, a small Sydney-based company better known for its PerformanceTest and BurnInTest benchmarking tools. OSForensics packages the core tasks of a computer forensic investigation — disk imaging, deleted file recovery, password extraction, memory analysis, hash-based evidence matching, timeline reconstruction and case reporting — into a single Windows application covering Windows, Mac, Linux and Android artifacts.
Founded in 1998, PassMark Software has stayed small and self-funded, with roughly a dozen employees split between its Sydney head office and a California branch. OSForensics is sold and resold through forensics-focused distributors that cater specifically to law enforcement and government investigators, such as Digital Intelligence and H-11 Digital Forensics, which is one of the more concrete signals that the tool sees real use in actual investigations rather than just marketing claims.
Its main differentiator in a market that includes far more expensive suites like EnCase and FTK is price and accessibility: OSForensics gives smaller law enforcement units, corporate investigators and IT security teams a full-featured forensics toolkit without enterprise forensic software budgets. It hasn’t been independently lab-tested or benchmarked against those larger suites in any evaluation found during this research, so claims about its completeness and reliability rest mainly on longevity and reseller/practitioner adoption rather than third-party validation.
Innovation Matrix Assessment
OSForensics has shipped a steady stream of version updates adding mobile (Android) and expanded file-system support over its product life, a reasonable pace for a small, self-funded team.
PassMark Software operates with roughly a dozen employees across two offices; that lean structure has sustained a niche forensics product for over a decade but limits capacity for large-scale enterprise support.
No funding events or acquisitions found; growth signals are limited to continued distribution through law-enforcement-focused resellers rather than any publicly reported expansion metrics.
Its main disruption is price and accessibility relative to enterprise forensic suites like EnCase and FTK, making forensic capability available to smaller units and teams, rather than introducing a fundamentally new investigative technique.
Distribution through law-enforcement-specialist resellers (Digital Intelligence, H-11 Digital Forensics) is a real, independently observable adoption signal, but no independent lab evaluation or benchmark against competing forensic suites was found.
Digital forensics and incident-response evidence handling remain core security operations functions, though OSForensics serves a narrower, more specialized slice of that market than full incident-response platforms.
Why CISOs Should Care
Gives smaller security, IT and law-enforcement teams a full-featured, affordable forensics toolkit for internal investigations and incident response without committing to an enterprise forensic suite budget.
What Makes It Different
Bundles the full range of forensic tasks — imaging, recovery, memory analysis, hashing, timelining, reporting — into one lower-cost application rather than requiring multiple specialized tools.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A longstanding, affordable niche forensics tool with real practitioner adoption through specialist resellers, but limited independent validation and a very small team behind it.
Editorial Note: Claims vs. Verified Findings
PassMark's description of OSForensics as 'incredibly powerful, fast and reliable' is vendor language. Its distribution through law-enforcement-focused resellers such as Digital Intelligence and H-11 Digital Forensics is independently observable evidence of real-world use; no independent lab benchmark against competing forensic suites was found.
Sources
Alternatives to OSForensics
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…