Free Tools

Security Tools

Built by forensic examiners with 20 years of investigative experience. No signup required to start.

Free tools across mobile and disk acquisition, data recovery, email and document forensics, web security, hash integrity, calculators, workflow and Windows privilege-escalation auditing.

Compare all forensics tools: how Sherlock Forensics stacks up against Cellebrite, Magnet AXIOM and X-Ways on price and capability, including the Cellebrite free alternative.

Choose the device you want to investigate

Forensic Desktop Software

Free + Pro ($295) · NEWWindows

Sherlock Forensics Recover

Sherlock Forensics Recover finds deleted files, carves lost data and rebuilds RAID, reading the true length of every file so what comes back opens.

Get Sherlock Forensics Recover
Free + Forensic Edition ($599) · NEWBuilt in RustWindows

iPhone and iPad Analyzer

iOS forensic software for Windows. Acquire and analyze iPhone or iPad logical backups. Encrypted-backup decryption, 200+ artifact views including deleted-content carving, keychain extraction, WhatsApp, Safari, locations and hidden-vault app detection. Court-ready HTML reports. Cellebrite and Magnet AXIOM alternative at $599 one-time (no subscription).

Get iPhone and iPad Analyzer
Free + Pro ($59) · NEWWindows

VISURAL

Make a photo and video library searchable by what is inside each file. Find any person, pet, place, sign or spoken word from one search box, with face and pet recognition, text-in-image reading, speech transcription and video timelines. Runs entirely on your Windows PC with no cloud and no account. Free up to 500 items, Pro $59 one-time for unlimited.

Get VISURAL
Free + Forensic EditionBuilt in RustWindowsLinux

PST Viewer

Open PST/OST files without Outlook. Search, export and verify email archives. Forensic reports. Forensic Edition from $67.

Get PST Viewer

Guide: How to open PST files without Outlook

Free + Forensic EditionBuilt in RustWindowsLinux

Android Acquirer

Android logical acquisition via ADB. Extract SMS, contacts, call logs, media and apps. Court-ready forensic reports. Forensic Edition from $399.

Get Android Acquirer
Free + Forensic Edition ($297)Built in RustWindows

NSF Viewer (Lotus Notes)

Open .nsf, .ntf, .nsg and mail.box files from IBM, HCL and Lotus Notes archives. No Notes client required. Pure-Rust standalone parser, cryptographic NoteID identity verification, court-ready PDF reports. Forensic Edition $297 lifetime.

Get NSF Viewer

Guide: How to open NSF files without Lotus Notes

Free + Pro ($29/yr)Built in RustWindowsLinux

Forensic PDF Viewer + Editor

View, edit and threat-scan PDFs without trusting them. Built-in phishing detection, JS/action scanning and safe-by-default Rust parser. Pro from $29/year.

Get PDF Editor

Guide: How to safely open unknown PDFs

Free + Forensic Edition ($67)Built in RustWindowsLinux

OCR Reader

Forensic OCR with per-word confidence scoring, ed25519 hash-chained audit trails and 7 export formats including EDRM XML v1.2. Batch OCR with 1-32 workers. Forensic Edition $67.

Get OCR Reader
Free + Forensic EditionBuilt in RustWindows

Universal Events Viewer

Windows event log triage in plain English. 16 one-click buttons including "Have I Been Hacked?" five-phase analysis. Forensic Edition from $97.

Get Events Viewer
Desktop - FreeBuilt in RustWindows

Disk Imager

Free forensic disk imager. Raw .dd and E01 output. Three-pass SHA-256 verification. Resumable. FTK Imager alternative.

Get Disk Imager
COMING SOONBuilt in RustWindows

Sherlock EoP Auditor

Windows privilege-escalation surface scanner. Map the local EoP surface of any Windows host the way an attacker would. Built by the lab that finds zero-days. Early-access list open.

Join early-access list
Free + Forensic EditionBuilt in RustWindowsLinux

MSG Viewer

Open Outlook .msg files without Outlook. SMTP transport chain, SPF/DKIM/DMARC, anomaly detection. Forensic Edition from $67.

Get MSG Viewer
Free + Forensic EditionBuilt in RustWindowsLinux

EML Viewer

Open RFC-822 .eml files without Outlook. SMTP transport chain, SPF/DKIM/DMARC, folder batch analysis. Opens Gmail Takeout and Thunderbird exports. Forensic Edition from $67.

Get EML Viewer
Free + Forensic EditionBuilt in RustWindowsLinux

Browser Viewer

Extract history, bookmarks, downloads and extensions from Chrome, Edge, Firefox, Brave, Opera, Vivaldi and Tor. Forensic Edition from $49.

Get Browser Viewer
Free + Forensic EditionBuilt in RustWindowsLinux

OST Viewer

Open Outlook OST files without Exchange or Office 365. View cached emails offline. Forensic reports. Forensic Edition from $67.

Get OST Viewer
Desktop - FreeBuilt in RustWindows

USB Write Blocker

Free forensic USB write blocker. One-click registry-level write protection for evidence drives. Essential for forensic imaging.

Get USB Blocker

Guide: How to block USB drives on Windows

Desktop - FreeBuilt in RustWindowsLinux

Hash Verifier

Drag-and-drop SHA256, SHA512, MD5, SHA1 calculator. Batch processing and hash comparison for forensic integrity.

Get Hash Verifier
Desktop - FreeBuilt in RustWindowsLinux

Metadata Inspector

View, export and strip EXIF, PDF and Office metadata. Privacy and forensic analysis.

Get Metadata Inspector

Scanners & Analyzers

Scanner

Hack Your Own Website

Guided security testing tool. Walk through the same passive checks that attackers use. Headers, DNS, SSL, exposed paths and more.

Launch Tool
Scanner

Security Scorecard

Enter your domain, get an instant letter grade. Checks SSL, security headers, DNS authentication, cookies and HTTPS enforcement.

Scan My Domain
Analyzer

Email Header Analyzer

Paste email headers. See visual hop trace, SPF/DKIM/DMARC authentication results, sender verification and spoofing detection.

Analyze Headers
Desktop - FreeBuilt in RustWindowsLinux

Port Scanner

Fast TCP port scanning for security assessments. Service detection and attack surface mapping.

Get Port Scanner
Calculator

File Hash Calculator

Drag and drop to generate MD5, SHA-1, SHA-256, SHA-512. Compare hashes. No file upload. Runs in your browser.

Hash a File
Analyzer

Metadata Viewer

View hidden EXIF, PDF and Office metadata. GPS locations, author info, dates. Strip before sharing.

View Metadata

Calculators

Calculator

Pentest Cost Calculator

5-step questionnaire. Get a realistic price range for your penetration test based on scope, compliance and timeline.

Get Estimate
Calculator

Breach Cost Calculator

What would a data breach cost your company? Industry-specific estimates. Build the business case for security investment.

Calculate Risk

Email and Privacy

Analyzer

Sherlock Forensics Email Analyzer

Forensic email analysis with sender verification, header parsing and authentication validation. Detect spoofed and manipulated messages.

Analyze Email
Privacy

Privacy Tools

Privacy assessment and data protection tools for individuals and organizations. Evaluate your digital privacy posture.

View Privacy Tools

Assessments

Assessment

Security Readiness Quiz

10 questions. 2 minutes. Find out where your organization stands and what gaps to close before your next audit.

Take Assessment
Decision Engine

Vendor Comparison

Answer 4 questions. Get matched with the right security vendor for your environment. Independent, vendor-neutral guidance.

Compare Vendors

Forensic Resources

Documentation

Chain of Custody

Proper evidence custody documentation ensures digital evidence remains admissible in court. Review our methodology and procedures.

View Methodology
Generator

Forensic Report Generator

Generate structured forensic reports with proper formatting for court submission. Consistent methodology documentation across all case types.

Generate Report

Sherlock Forensics ships free interactive security and forensic tools built by CISSP-certified examiners in Vancouver. Email forensics: Sherlock Forensics PST Viewer, Sherlock Forensics OST Viewer, MSG viewer with SMTP transport chain analysis, EML viewer, email header analyzer with SPF DKIM DMARC spoofing detection and Sherlock Forensics Email Analyzer. Disk and mobile acquisition: Sherlock Forensics Disk Imager for forensic acquisition with chain of custody, Sherlock Forensics iPhone and iPad Analyzer for iOS logical acquisition, Sherlock Forensics Android Acquirer for logical Android acquisition and Sherlock Forensics USB Write Blocker for write-protected forensic imaging. Web and network: free website security scorecard with letter grade, Sherlock Forensics Port Scanner as a free Nmap alternative for Windows and Hack Your Own Website interactive guided security testing. Document forensics: Sherlock Forensics NSF Viewer for Lotus Notes archives, Sherlock Forensics PDF Viewer + Editor, Sherlock Forensics OCR Reader, Sherlock Forensics Browser Viewer for forensic browser history extraction and Sherlock Forensics Universal Events Viewer for Windows event log triage. Hash and metadata integrity: Sherlock Forensics Hash Calculator, free hash verifier, metadata viewer and Sherlock Forensics Metadata Inspector. Calculators and decision tools: pentest cost calculator, breach cost ROI calculator, security readiness assessment quiz and a vendor comparison decision engine for forensic software selection. Workflow tools: chain of custody template, forensic report generator and privacy compliance tools. Sherlock EoP Auditor for Windows privilege-escalation surface scanning is in early access. Every tool is free to use. CISSP, ISSAP and ISSMP certified forensic examiners. 20 years of court-defensible digital forensics in British Columbia.

Beyond Free Tools

These tools are the starting point. Not the finish line.

Free tools cover basic security checks. A professional penetration test from Sherlock Forensics covers 200+ attack vectors: business logic flaws, authentication bypass, privilege escalation, API security and manual exploitation. From $1,500 USD.

Since 20064.8/5 ratingCISSP, ISSAP, ISSMP certified
Get a Professional Assessment

Questions

About Our Tools

Are these tools really free?
Our interactive security tools are free to use with no time limits or feature restrictions. Some tools ask for an email address before showing full results so we can send you a copy of your report. We do not sell or share your information.
Who built these tools?
Sherlock Forensics, a Vancouver cybersecurity firm with 20+ years experience. The tools reflect our professional methodology, simplified for self-service.
Are the scans safe?
Yes. Our scanners perform only passive checks using publicly available information. No exploitation, no malicious payloads, no data modification.
Can these replace a professional pentest?
No. These cover basic checks. A professional test covers 200+ attack vectors including business logic, authentication bypass and manual exploitation.
What should I do after using these tools?
Address failed checks using the remediation guidance. For comprehensive assessment, call 888.883.4550 for a free consultation.