: Introduced the ability to automatically create a Virtual Machine (VM) directly from forensic disk images, allowing investigators to boot the suspect's OS in a safe, sandboxed environment. 🔍 Advanced Data Recovery & Carving

Implemented minimum size requirements for carved files (e.g., 126 bytes for JPGs) to reduce false positives. 🕵️ New Artifact Analysis

: This module evolved from a simple prefetch viewer to include a wider range of program activity traces.

: Added support for carving Master File Table (MFT) records on non-NTFS quick-formatted volumes, which allows for recovering files that would otherwise be lost after a format. Improved Media Handling : Added a quality level indicator for thumbnail previews.

: The password module was updated to automatically scan "Windows.old" folders for legacy credentials. 🛠️ Workflow & Security

: A new housekeeping button verifies the digital signatures of the OSForensics executable itself to ensure the program has not been tampered with. Using the OSForensics Workflow

Below is a feature highlight of the version 10 series improvements: 🚀 Speed and Imaging Enhancements

Accessibility Toolbar