PassMark OSForensics Professional 3.3 Build 1004
OSForensics allows you to identify suspicious files and activity with hash matching, drive signature comparisons, e-mails, memory and binary data.
It lets you extract forensic evidence from computers quickly with advanced file searching and indexing and enables this data to be managed effectively.
Features:
- Discover Forensic Evidence Faster
- Identify Suspicious Files and Activity
- Manage Your Digital Investigation
- Import and export of hash sets
- Customizable system information gathering
- No limts on the amount of cases being managed through OSForensics
- Restoration of multiple deleted files in one operation
- List and search for alternate file streams
- Sort image files by colour
- Disk indexing and searching not restricted to a fixed number of files
- No watermark on web captures
- Multi-core acceleration for file decryption
- Customizable System Information Gathering
- View NTFS directory $I30 entries to identify potential hidden/deleted files
Changelog:
v3.3.1004 (2016-04-12):
-
Case Manager
- Added warning when attempting to add the entire image to case when there is a partition table
- Allow the option to select the "entire image file" when adding images to case
-
File Indexer
- New Zoom builds with added recognition for extensions .plt and .dxf to index filename only
- Fixed stack/buffer overflow issue when indexing PST emails.
-
Raw disk viewer
- When viewing the raw sectors of entire images, the partition table info is now decoded
-
Search Index
- Fixed special characters such as '&' in the filepath from the search results not being decoded properly
-
Misc
- Device dropdown list now includes the image file's partition (or "Entire image")
- Fixed bug with not being able to read the raw bytes of image files using UNC paths
- Accessing the entire image file with a valid partition table (ie. without specifying a partition) no longer returns error
v3.3.1003 (2016-04-06):
-
Email Viewer
- Fixed stack overflow crash bug when saving MSG attachment with multiple levels of nesting
-
File Indexer
- New Zoom indexer build, fixed a crash bug for nested MSG files within PST files
v3.3.1002 (2016-03-23):
-
Deleted Files - FileCarving
- Fixed Crash. TIF file format has internal pointers to location within the file, when these pointer contains a corrupted/invalid value, it would possibly cause OSForensics to crash.
- Added slider to configuration to allow selection of start and end percent/location of drive to carve.
- Fixed possible crash when searching for HFS+ deleted files.
-
File Indexer
- New Zoom build, fixed issues with not starting indexing on HFS image with "Invalid folder" errors.
-
Misc
- Fixed retrieving file attributes on non-ntfs file systems
- Fixed possible crash when access HFS+ filesystem
- Added detection of file system for MBR partitions due to possible differences in reported partition type and actual file system
Homepage: http://www.osforensics.com
Changelog: http://www.osforensics.com/whatsnew.html
Release Date: 2016-04-12
OS: Windows
Language: English
Download Page: http://www.osforensics.com/download.html
DOWNLOAD:
==============================
Installer (52.02 MB): http://www.osforensics.com/downloads/osf.exe
Patch (67 KB):
==============================
Note: Thanks to @CoolZoid for providing the patch: http://www.nsaneforums.com/topic/266118-passmark-osforensics-professional-33-build-1003/?do=findComment&comment=1073983