Best Digital Forensics Software in 2026

In short: Paraben E3 Forensic Platform is ranked #1 of 29 as of 4 October 2026, ahead of OSForensics and Magnet AXIOM Cyber. The best-ranked option with a free plan is CAINE. The lowest first paid tier on this page is Exterro FTK Imager at $41.58/mo.

Digital forensics software is used to collect and examine digital evidence during investigations. Compare evidence sources and supported platforms alongside disk imaging, memory forensics, and mobile forensics to see which forms of examination are covered. Export formats and case collaboration can help you assess how findings are prepared and shared. Free-plan availability and paid-from pricing add cost context. Paraben E3 Forensic Platform, OSForensics, and Exterro FTK Imager are among the entries to consider. Match the listed capabilities to the evidence you work with and the investigative workflows you need to support.

29 digital forensics software ranked on what their makers publish — plans and prices, free tiers, platforms and the facts on their own pages.

29ranked
8free plans on this page
$41.58/molowest paid tier
4 Oct 2026last checked

Recognised 40% · Phone app 26% · Documented 20% · Free plan 14% of the score

  1. 1 Paraben E3 Forensic Platform iPhone + Android RecognisedPhone appDocumentedFree plan 9.2$58.25/mo Evidence sources: Smartphones, computers, disk images, memory dumps, email, chat databases, cloud services, social media, IoT devices, game consoles, archives, and OSINT dataMobile forensics: YesDisk imaging: Yes
  2. 2 OSForensics Android only RecognisedPhone appDocumentedFree plan 8.0 Evidence sources: Windows, Mac, Linux, Android, iOS/macOS file systems, disk images, memory dumps, emails, browser data, registry hives, SQLite and ESE databasesMobile forensics: YesDisk imaging: Yes
  3. 3 Magnet AXIOM Cyber No phone app RecognisedPhone appDocumentedFree plan 7.1 Evidence sources: Mobile devices; computer drives and forensic images; Windows, macOS, Linux, and Chromebook files and folders; Windows memory dumps; cloud services; remote endpointsMobile forensics: YesDisk imaging: Yes
  4. 4 Autopsy No phone app RecognisedPhone appDocumentedFree plan 7.0
  5. 5 OpenText Forensic No phone app RecognisedPhone appDocumentedFree plan 7.0 Evidence sources: Windows, macOS, Linux, mobile devices and backups, removable drives, encrypted volumes, Microsoft 365, Facebook, cloud storage, file systemsMobile forensics: YesDisk imaging: Yes
  6. 6 CAINE No phone app RecognisedPhone appDocumentedFree plan 7.0Free Evidence sources: raw/dd disk images; EnCase files; databases; internet histories; Windows registries; deleted files; EXIF data; volatile memory dumps; Android and iPod devicesMobile forensics: YesDisk imaging: Yes
  7. 7 Oxygen Forensic Detective No phone app RecognisedPhone appDocumentedFree plan 6.9 Evidence sources: Mobile devices; computers and external media; cloud services and app data; drones; vehicle systems; IoT sources; warrant returns; account data; third-party forensic extractionsMobile forensics: YesDisk imaging: Yes
  8. 8 X-Ways Forensics No phone app RecognisedPhone appDocumentedFree plan 6.9 Evidence sources: Raw DD images, ISO, VHD, VHDX, VDI, VMDK, physical disks, RAIDs, filesystems, Android/iOS data imported through third-party tools, iTunes backupsMobile forensics: YesDisk imaging: Yes
  9. 9 SUMURI PALADIN No phone app RecognisedPhone appDocumentedFree plan 6.9Free Evidence sources: Disk images, local disks, logical files, unallocated-space images, Autopsy Logical Imager results, XRY text exports, mobile and vehicle dataMobile forensics: YesDisk imaging: Yes
  10. 10 Tsurugi Linux No phone app RecognisedPhone appDocumentedFree plan 6.8Free Evidence sources: disk images; volatile memory; mobile devices; file systems; OS artifacts; cloud environments; virtual machines; network dataMobile forensics: YesDisk imaging: Yes
  11. 11 Cellebrite Inseyets No phone app RecognisedPhone appDocumentedFree plan 6.7 Evidence sources: iOS devices; Android devices; mobile applications; cloud data; encrypted and containerized files; SIM cards; portable media; UAV evidenceMobile forensics: Yes
  12. 12 Plaso No phone app RecognisedPhone appDocumentedFree plan 6.6Free Evidence sources: Storage-media images, files, directories, devices, logs, databases, Windows Registry data, Android and iOS artifactsMobile forensics: YesDisk imaging: Yes
  13. 13 Exterro FTK Imager No phone app RecognisedPhone appDocumentedFree plan 6.5$41.58/mo Evidence sources: Live enterprise endpoints; Windows, macOS, and selected Linux artifacts; Microsoft 365; Exchange; SharePoint; OneDrive; Google Workspace; Gmail; Google Drive; Slack; Microsoft Teams; Confluence; AFF4; E01; AD1; RAW/DDMobile forensics: NoDisk imaging: Yes
  14. 14 ADF Triage-G2 No phone app RecognisedPhone appDocumentedFree plan 6.3 Evidence sources: iOS devices, Android devices, computers, USB devices, storage media, documents, emails, text communications, and digital imagesMobile forensics: YesDisk imaging: Yes
  15. 15 SUMURI RECON LAB No phone app RecognisedPhone appDocumentedFree plan 6.3 Evidence sources: macOS, Windows, Linux, iOS, Android, Google Takeout, AFF4 images, Cellebrite extractions, GrayKey backups, ADB Android backupsMobile forensics: YesDisk imaging: Yes
  16. 16 Belkasoft X Forensic No phone app RecognisedPhone appDocumentedFree plan 6.2
  17. 17 MSAB XRY No phone app RecognisedPhone appDocumentedFree plan 6.2 Evidence sources: iOS devices; Android devices; smartphone apps; SIM cards; SD/memory cards; cloud storage; social-media services; iCloud backups; GPS devices; device RAM; full device dumps and binary filesMobile forensics: YesDisk imaging: Yes
  18. 18 NetworkMiner No phone app RecognisedPhone appDocumentedFree plan 6.2Free
  19. 19 MOBILedit Forensic No phone app RecognisedPhone appDocumentedFree plan 6.0 Evidence sources: Mobile phones, smartwatches, cloud services, applications, backups, physical images, filesystems, messages, calls, media, passwords, and deleted dataMobile forensics: YesDisk imaging: Yes
  20. 20 Arkime No phone app RecognisedPhone appDocumentedFree plan 6.0Free
  21. 21 SIFT Workstation No phone app RecognisedPhone appDocumentedFree plan 5.9
  22. 22 Volatility 3 No phone app RecognisedPhone appDocumentedFree plan 5.9Free Evidence sources: volatile memory (RAM) samples and memory images from Windows, Linux, and macOSMobile forensics: NoDisk imaging: No
  23. 23 The Sleuth Kit No phone app RecognisedPhone appDocumentedFree plan 5.7 Evidence sources: Raw/dd, E01/EnCase, VHD, VMDK, AFF images; NTFS, FAT, ExFAT, APFS, UFS 1/2, EXT2/3/4, HFS, ISO 9660, and YAFFS2 file systemsMobile forensics: YesDisk imaging: Yes
  24. 24 Timesketch No phone app RecognisedPhone appDocumentedFree plan 5.5 Evidence sources: Plaso storage files, CSV, JSON, JSONL, Pandas DataFrame, Python dict, XLS/XLSX
  25. 25 X-Ways Imager No phone app RecognisedPhone appDocumentedFree plan 5.3 Evidence sources: Physical disks, SSDs, partitions, raw images, E01 images, disk-based RAID systemsMobile forensics: NoDisk imaging: Yes

Is your app on this list?

Numbered spots on this list can be sponsored. They are labelled, and the editorial order and scores never change for payment.

Questions about this list

Which digital forensics software is ranked first on Samsung Mobile US Press?

Paraben E3 Forensic Platform is ranked #1 of 29 with a score of 9.2. OSForensics is second and Magnet AXIOM Cyber third.

How many of these have a free plan?

8 of the 25 on this page publish a free plan on their own pricing pages.

Which is the cheapest paid option?

On this page, Exterro FTK Imager has the lowest first paid tier we found: $41.58/mo.

How is this list ranked?

Ranked mobile-first: a phone app alongside the web or desktop product, a free tier and the depth of its documentation. Paid placements never change a rank.

More in IT & Infrastructure

All IT & infrastructure lists