Legal Cyber Academy
ToolPaidCurrent

X-Ways Forensics

X-Ways Software Technology AG · 2026

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.

Who it is for, and when

X-Ways is the examiner's tool for working close to the disk: extremely fast volume and file system handling, a genuine hex and directory-entry view alongside the interpreted one, and fine-grained control over what gets processed. Practitioners who need to reason about file system internals, carve deliberately, or verify another suite's finding at the byte level tend to prefer it. The perpetual licence and modest hardware appetite also make it attractive to sole practitioners, and X-Ways Investigator is a cheaper cut-down edition.

What it does not cover

Pricing is not published on the product page — quotes are retrieved through the order pages, and downloads are restricted to existing customers with trials available only to law enforcement, government, and some corporations. The interface is dense and unforgiving, with a learning curve that makes it a poor first suite. Mobile and cloud coverage is minimal compared with Magnet or Cellebrite, and it is Windows-only.

Go to the source

Open at x-ways.net (opens in a new tab)

https://www.x-ways.net/forensics/

Details

Type
Tool
Written for
AdvancedAdvanced
Publisher
X-Ways Software Technology AG
Year
2026
Topics
commercial-suite, file-systems, windows, imaging, triage, reporting
Checked at source
  • An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.

  • The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.

  • Case-driven walkthroughs of Windows examinations where the narration is the analyst's thought process: what question is being asked, which artifact is chosen next, and why a hypothesis was dropped. Deliberately excludes the artifact reference material from the author's other books.

  • A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.

  • FTK Imager

    Partly free

    A free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.