Best Digital Forensics Software in 2026
Updated
In short: Paraben E3 Forensic Platform is ranked #1 of 29 as of 4 October 2026, ahead of OSForensics and Magnet AXIOM Cyber. The best-ranked option with a free plan is CAINE. The lowest first paid tier on this page is Exterro FTK Imager at $41.58/mo.
Digital forensics software is used to collect and examine digital evidence during investigations. Compare evidence sources and supported platforms alongside disk imaging, memory forensics, and mobile forensics to see which forms of examination are covered. Export formats and case collaboration can help you assess how findings are prepared and shared. Free-plan availability and paid-from pricing add cost context. Paraben E3 Forensic Platform, OSForensics, and Exterro FTK Imager are among the entries to consider. Match the listed capabilities to the evidence you work with and the investigative workflows you need to support.
29 digital forensics software ranked on what their makers publish — plans and prices, free tiers, platforms and the facts on their own pages.
Recognised 40% · Phone app 26% · Documented 20% · Free plan 14% of the score
- 1 Paraben E3 Forensic Platform iPhone + Android RecognisedPhone appDocumentedFree plan 9.2$58.25/mo Evidence sources: Smartphones, computers, disk images, memory dumps, email, chat databases, cloud services, social media, IoT devices, game consoles, archives, and OSINT dataMobile forensics: YesDisk imaging: Yes
- 2 OSForensics Android only RecognisedPhone appDocumentedFree plan 8.0 Evidence sources: Windows, Mac, Linux, Android, iOS/macOS file systems, disk images, memory dumps, emails, browser data, registry hives, SQLite and ESE databasesMobile forensics: YesDisk imaging: Yes
- 3 Magnet AXIOM Cyber No phone app RecognisedPhone appDocumentedFree plan 7.1 Evidence sources: Mobile devices; computer drives and forensic images; Windows, macOS, Linux, and Chromebook files and folders; Windows memory dumps; cloud services; remote endpointsMobile forensics: YesDisk imaging: Yes
- 4 Autopsy No phone app RecognisedPhone appDocumentedFree plan 7.0
- 5 OpenText Forensic No phone app RecognisedPhone appDocumentedFree plan 7.0 Evidence sources: Windows, macOS, Linux, mobile devices and backups, removable drives, encrypted volumes, Microsoft 365, Facebook, cloud storage, file systemsMobile forensics: YesDisk imaging: Yes
- 6 CAINE No phone app RecognisedPhone appDocumentedFree plan 7.0Free Evidence sources: raw/dd disk images; EnCase files; databases; internet histories; Windows registries; deleted files; EXIF data; volatile memory dumps; Android and iPod devicesMobile forensics: YesDisk imaging: Yes
- 7 Oxygen Forensic Detective No phone app RecognisedPhone appDocumentedFree plan 6.9 Evidence sources: Mobile devices; computers and external media; cloud services and app data; drones; vehicle systems; IoT sources; warrant returns; account data; third-party forensic extractionsMobile forensics: YesDisk imaging: Yes
- 8 X-Ways Forensics No phone app RecognisedPhone appDocumentedFree plan 6.9 Evidence sources: Raw DD images, ISO, VHD, VHDX, VDI, VMDK, physical disks, RAIDs, filesystems, Android/iOS data imported through third-party tools, iTunes backupsMobile forensics: YesDisk imaging: Yes
- 9 SUMURI PALADIN No phone app RecognisedPhone appDocumentedFree plan 6.9Free Evidence sources: Disk images, local disks, logical files, unallocated-space images, Autopsy Logical Imager results, XRY text exports, mobile and vehicle dataMobile forensics: YesDisk imaging: Yes
- 10 Tsurugi Linux No phone app RecognisedPhone appDocumentedFree plan 6.8Free Evidence sources: disk images; volatile memory; mobile devices; file systems; OS artifacts; cloud environments; virtual machines; network dataMobile forensics: YesDisk imaging: Yes
- 11 Cellebrite Inseyets No phone app RecognisedPhone appDocumentedFree plan 6.7 Evidence sources: iOS devices; Android devices; mobile applications; cloud data; encrypted and containerized files; SIM cards; portable media; UAV evidenceMobile forensics: Yes
- 12 Plaso No phone app RecognisedPhone appDocumentedFree plan 6.6Free Evidence sources: Storage-media images, files, directories, devices, logs, databases, Windows Registry data, Android and iOS artifactsMobile forensics: YesDisk imaging: Yes
- 13 Exterro FTK Imager No phone app RecognisedPhone appDocumentedFree plan 6.5$41.58/mo Evidence sources: Live enterprise endpoints; Windows, macOS, and selected Linux artifacts; Microsoft 365; Exchange; SharePoint; OneDrive; Google Workspace; Gmail; Google Drive; Slack; Microsoft Teams; Confluence; AFF4; E01; AD1; RAW/DDMobile forensics: NoDisk imaging: Yes
- 14 ADF Triage-G2 No phone app RecognisedPhone appDocumentedFree plan 6.3 Evidence sources: iOS devices, Android devices, computers, USB devices, storage media, documents, emails, text communications, and digital imagesMobile forensics: YesDisk imaging: Yes
- 15 SUMURI RECON LAB No phone app RecognisedPhone appDocumentedFree plan 6.3 Evidence sources: macOS, Windows, Linux, iOS, Android, Google Takeout, AFF4 images, Cellebrite extractions, GrayKey backups, ADB Android backupsMobile forensics: YesDisk imaging: Yes
- 16 Belkasoft X Forensic No phone app RecognisedPhone appDocumentedFree plan 6.2
- 17 MSAB XRY No phone app RecognisedPhone appDocumentedFree plan 6.2 Evidence sources: iOS devices; Android devices; smartphone apps; SIM cards; SD/memory cards; cloud storage; social-media services; iCloud backups; GPS devices; device RAM; full device dumps and binary filesMobile forensics: YesDisk imaging: Yes
- 18 NetworkMiner No phone app RecognisedPhone appDocumentedFree plan 6.2Free
- 19 MOBILedit Forensic No phone app RecognisedPhone appDocumentedFree plan 6.0 Evidence sources: Mobile phones, smartwatches, cloud services, applications, backups, physical images, filesystems, messages, calls, media, passwords, and deleted dataMobile forensics: YesDisk imaging: Yes
- 20 Arkime No phone app RecognisedPhone appDocumentedFree plan 6.0Free
- 21 SIFT Workstation No phone app RecognisedPhone appDocumentedFree plan 5.9
- 22 Volatility 3 No phone app RecognisedPhone appDocumentedFree plan 5.9Free Evidence sources: volatile memory (RAM) samples and memory images from Windows, Linux, and macOSMobile forensics: NoDisk imaging: No
- 23 The Sleuth Kit No phone app RecognisedPhone appDocumentedFree plan 5.7 Evidence sources: Raw/dd, E01/EnCase, VHD, VMDK, AFF images; NTFS, FAT, ExFAT, APFS, UFS 1/2, EXT2/3/4, HFS, ISO 9660, and YAFFS2 file systemsMobile forensics: YesDisk imaging: Yes
- 24 Timesketch No phone app RecognisedPhone appDocumentedFree plan 5.5 Evidence sources: Plaso storage files, CSV, JSON, JSONL, Pandas DataFrame, Python dict, XLS/XLSX
- 25 X-Ways Imager No phone app RecognisedPhone appDocumentedFree plan 5.3 Evidence sources: Physical disks, SSDs, partitions, raw images, E01 images, disk-based RAID systemsMobile forensics: NoDisk imaging: Yes
Is your app on this list?
Numbered spots on this list can be sponsored. They are labelled, and the editorial order and scores never change for payment.
Questions about this list
Which digital forensics software is ranked first on Samsung Mobile US Press?
Paraben E3 Forensic Platform is ranked #1 of 29 with a score of 9.2. OSForensics is second and Magnet AXIOM Cyber third.
How many of these have a free plan?
8 of the 25 on this page publish a free plan on their own pricing pages.
Which is the cheapest paid option?
On this page, Exterro FTK Imager has the lowest first paid tier we found: $41.58/mo.
How is this list ranked?
Ranked mobile-first: a phone app alongside the web or desktop product, a free tier and the depth of its documentation. Paid placements never change a rank.






