X-Ways Forensics
X-Ways Software Technology AG · 2026
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.
Who it is for, and when
X-Ways is the examiner's tool for working close to the disk: extremely fast volume and file system handling, a genuine hex and directory-entry view alongside the interpreted one, and fine-grained control over what gets processed. Practitioners who need to reason about file system internals, carve deliberately, or verify another suite's finding at the byte level tend to prefer it. The perpetual licence and modest hardware appetite also make it attractive to sole practitioners, and X-Ways Investigator is a cheaper cut-down edition.
What it does not cover
Pricing is not published on the product page — quotes are retrieved through the order pages, and downloads are restricted to existing customers with trials available only to law enforcement, government, and some corporations. The interface is dense and unforgiving, with a learning curve that makes it a poor first suite. Mobile and cloud coverage is minimal compared with Magnet or Cellebrite, and it is Windows-only.
Go to the source
Open at x-ways.net (opens in a new tab)https://www.x-ways.net/forensics/
Details
- Type
- Tool
- Written for
- AdvancedAdvanced
- Publisher
- X-Ways Software Technology AG
- Year
- 2026
- Topics
- commercial-suite, file-systems, windows, imaging, triage, reporting
- Checked at source
Related entries
Autopsy
FreeAn open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.
The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.
Case-driven walkthroughs of Windows examinations where the narration is the analyst's thought process: what question is being asked, which artifact is chosen next, and why a hypothesis was dropped. Deliberately excludes the artifact reference material from the author's other books.
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.
FTK Imager
Partly freeA free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.