Wingetlywingetly
← All apps

OSForensics

by PassMark Softwarev11.1.1016.0

Last updated

Digital investigations for a new era

Install with winget

$ winget install --id PassMark.OSForensics --exact --version 11.1.1016.0

Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.

Silent install command for OSForensics

OSForensics uses EXE (Inno Setup). The silent install switches are /VERYSILENT /SUPPRESSMSGBOXES /NORESTART.

One-line silent install (x86, machine scope)
OSForensics.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART

See the full silent install reference for OSForensics

Built by Pckgr

For Intune admins

Stop chasing app updates. Pckgr patches them for you.

Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.

Start free 30-day trial

No credit card required.

About

- Identify suspicious files and activity

- Extract evidence from computers quickly

- Manage your investigation

Installers · v11.1.1016.0

ArchitectureTypeScopeInstallDownload
x86EXE
Inno Setup
machineDirect

Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.

Security

3 known CVEs via NVD

  • high7.8Patched in wingetCVE-2020-15481affects v7.1Nov 13, 2020

    An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling...

  • high8.8Patched in wingetCVE-2020-15480affects <=7.1Aug 7, 2020

    An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs). This could lead to a...

  • high8.8Patched in wingetCVE-2020-15479affects <=7.1Aug 7, 2020

    An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The driver's IOCTL request handler attempts to copy the input buffer onto the stack without checking its size and can cause a buffer overflow. This could lead to...

Source: NVD, updated 5h ago. Patch status is best-effort: NVD's fix version is compared against the latest version in winget, but the two version formats don't always align. Confirm with the vendor advisory before treating any specific build as safe.

Related apps

  • KeyboardTestPassMark Software
    PassMark.KeyboardTestv4.0.1003

    Test desktop and laptop computer keyboards

  • ImageUSBPassMark Software
    PassMark.ImageUSBv1.5.1007

    ImageUSB is a free utility which lets you write an image concurrently to multiple USB Flash Drives.

  • Volatility WorkbenchPassMark Software
    PassMark.VolatilityWorkbenchv3.0.1014

    Volatility Workbench is a graphical user interface (GUI) for the Volatility tool.

  • DiskCheckupPassMark Software
    PassmarkSoftware.DiskCheckupv3.6.1001.0

    SMART hard drive monitoring utility

  • WirelessMon 5PassMark Software
    PassMark.WirelessMonv5.0.1004

    Monitor wireless adapters and WiFi access points

  • RebooterPassMark Software
    PassMark.Rebooterv1.3.1007

    PC Shutdown, Reboot or Logout utility

More from PassMark Software.

Frequently asked questions

How do I install OSForensics on Windows?
Open Windows Terminal, PowerShell, or Command Prompt and run: winget install --id PassMark.OSForensics --exact --version 11.1.1016.0. winget downloads the installer from PassMark Software and runs it. Requires Windows 10 (1809+) or Windows 11.
How do I install OSForensics silently for unattended deployment?
Add --silent and accept the agreements upfront: winget install --id PassMark.OSForensics --exact 11.1.1016.0 --silent --accept-package-agreements --accept-source-agreements. This is the variant Intune, Configuration Manager, and other deployment tools should use.
What are the silent install switches for OSForensics?
OSForensics uses EXE (Inno Setup). Run the downloaded installer with: OSForensics.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART. The silent switches are /VERYSILENT /SUPPRESSMSGBOXES /NORESTART.
How do I uninstall OSForensics via winget?
Run: winget uninstall --id PassMark.OSForensics --exact. Add --silent for unattended uninstalls. winget will use the registered uninstaller from OSForensics's Apps & Features entry.
Is OSForensics free?
OSForensics is distributed under Proprietary. Refer to the publisher (https://www.osforensics.com/download.html) for the full license terms - Wingetly itself does not charge for installation.
Does OSForensics work on Windows 10?
Yes, as long as your Windows 10 build supports winget (1809 or newer). winget ships with App Installer on Windows 10/11 and pulls OSForensics directly from the publisher.
How do I keep OSForensics up to date?
Run winget upgrade --id PassMark.OSForensics --exact, or winget upgrade --all to update everything winget tracks. We index 1 version of OSForensics from microsoft/winget-pkgs.