Support

Need help with dfirOS? We're here for you.

✉️

Email Support

For bug reports, feature requests, or general questions — drop us an email and we'll get back to you as quickly as we can.

[email protected]

Frequently Asked Questions

dfirOS supports EnCase E01, AFF4, raw disk images (.dd, .raw, .img, .dmg, .iso), iTunes backups, TAR/ZIP archives, and local folders. File systems include NTFS, APFS, HFS+, ext4, FAT32, and exFAT with MBR, GPT, and Apple Partition Map support. It also includes 30+ format previews (Registry hives, EVTX, Prefetch, SQLite, Plist, MFT, and more) and 180+ forensic artifact scanners.
No. dfirOS is strictly read-only. It never writes to, modifies, or alters your forensic evidence in any way.
All core features work entirely offline. Your forensic data never leaves your device. AI-assisted analysis requires an internet connection unless using a local Ollama model.
dfirOS runs on macOS and Windows.