Software Pricing

Sherlock Forensics Software Pricing

Sherlock Forensics ships 7 forensic software products from $29 USD (Browser Viewer) to $399 USD (Android Acquirer). All software is one-time purchase with no subscription. The free tier of every product is feature-complete for view-and-triage workflows. Paid tiers add export, batch processing, court-ready forensic reports and chain-of-custody logging.

Browser forensics

Browser Viewer Forensic Edition

$29 USD

Browser-artifact triage for Chrome, Edge, Firefox, Safari and Tor.

  • Recovers history, downloads, cookies, autofill and bookmarks across 5 browser families
  • Recovers from a stopped Windows machine with no Chrome instance running
  • Free to view, $29 USD one-time to export and bulk-process
Buy at $29

Endpoint security

USB Blocker Pro

$39 USD

Windows physical-port lockdown for forensic and DLP workstations.

  • Blocks mass storage, MTP, phone tethering and rubber-ducky HID injection at the kernel layer
  • Tamper-detection event log with operator authentication for unlock
  • Free Watchdog tier, $39 USD Pro tier with policy export
Buy at $39

Email forensics

PST Viewer Forensic Edition

$67 USD

Pure-Rust PST, OST, MSG and EML viewer. No Outlook required.

  • Deleted-item recovery via 4 carving methods (dumpster, B-tree, slack space, page scan)
  • Court-ready PDF reports with per-message SHA-256 and sender-IP attribution
  • Single $67 USD license unlocks PST, OST, MSG and EML viewers
Buy at $67

Document forensics

OCR Reader Forensic Edition

$67 USD

Forensic OCR on receipts, screenshots, scanned PDFs and damaged documents.

  • Tesseract 5 LSTM engine with Sherlock preprocessing pipeline (smart bicubic upscaling, adaptive binarization, deskew, multi-pass voting)
  • Bates-numbered evidence export with per-word confidence sidecar and EDRM XML v1.2 output
  • Free to read, $67 USD one-time for batch operations and signed forensic reports
Buy at $67

Event log forensics

Universal Events Viewer Forensic Edition

$97 USD

Windows event log and EVTX forensic triage at IR speed.

  • Reads .evtx and .evt with plain-English narrative translation alongside raw event JSON
  • Automated detection rules for Kerberos ticket abuse, credential dumping and lateral movement signatures across the Windows security log timeline
  • Free triage tier, $97 USD Forensic Edition for chain-of-custody export and forensic PDF reports
Buy at $97

Lotus Notes forensics

NSF Viewer Forensic Edition

$297 USD

World's first pure-Rust Lotus Notes parser. No HCL or IBM runtime required.

  • Direct NSF-to-PST conversion for Outlook import alongside structured JSONL forensic export
  • EDRM XML metadata for Relativity, Concordance, Logikcull, Reveal and Everlaw ingest
  • Free to view, $297 USD lifetime Forensic Edition (EV code-signed, single 6.5 MB exe)
Buy at $297

Mobile forensics

Android Acquirer Forensic Edition

$399 USD

Android logical acquisition with court-ready chain of custody.

  • Logical acquisition over ADB across Android 6 Marshmallow through Android 15 (Samsung, Pixel, OnePlus, Xiaomi, Motorola and all major OEMs)
  • SHA-256 evidence container with verifiable manifest and operator attribution
  • Free triage tier, $399 USD Forensic Edition for full acquisition and reporting
Buy at $399

All prices in US dollars. One-time purchase. No subscription. Free updates included. PST Viewer Forensic Edition unlocks the PST, OST, MSG and EML viewers under a single license.

Looking for pen testing or security audit services instead? See the security assessment order page.