Support
Need help with dfirOS? We're here for you.
✉️
Email Support
For bug reports, feature requests, or general questions — drop us an email and we'll get back to you as quickly as we can.
[email protected] →Frequently Asked Questions
dfirOS supports EnCase E01, AFF4, raw disk images (.dd, .raw, .img, .dmg, .iso), iTunes backups, TAR/ZIP archives, and local folders. File systems include NTFS, APFS, HFS+, ext4, FAT32, and exFAT with MBR, GPT, and Apple Partition Map support. It also includes 30+ format previews (Registry hives, EVTX, Prefetch, SQLite, Plist, MFT, and more) and 180+ forensic artifact scanners.
No. dfirOS is strictly read-only. It never writes to, modifies, or alters your forensic evidence in any way.
All core features work entirely offline. Your forensic data never leaves your device. AI-assisted analysis requires an internet connection unless using a local Ollama model.
dfirOS runs on macOS and Windows.