Download Crow Eye
Both downloads are the Crow-Eye Windows app (a native .exe, no separate setup). The Installer (recommended) is the newest version with the latest investigation improvements and automatic updates; the Portable edition is a standalone build you run straight from a USB stick.
Want to see how it works?
Watch Demo VideoSystem Requirements
- Operating System: Windows 10 or Windows 11 (64-bit)
- Administrator Rights: Required for live system analysis
- RAM: Minimum 4GB (8GB recommended for large datasets)
- Storage: 500MB free space for application + space for case data
- Python: Not required for standalone EXE (included for source builds)
Important Notes
- Executable: The Crow Eye package is provided as a ZIP containing the self-contained Crow-Eye.exe. Simply extract and run - no installation needed.
- Administrator Access: For live system analysis, run Crow Eye with administrator privileges to access all forensic artifacts.
- Antivirus Warning: Some antivirus software may flag forensic tools. This is a false positive due to the engine's system-level access requirements.
- Source Code: If you prefer to build from source or contribute to development, clone the repository and follow the setup instructions in the README.
- Updates: Check the GitHub releases page regularly for the latest version and security updates.
- Having Issues? Visit the Troubleshooting Guide for common problems and solutions.
Quick Start Guide
1. Download
Choose your preferred download method above. For most users, the EXE (ZIP) is recommended.
2. Run as Administrator
Extract the ZIP, right-click Crow-Eye.exe and select "Run as administrator" to ensure full access to system artifacts.
3. Create a Case
Launch the application, create a new case, and start analyzing Windows forensic artifacts.
Need Help?
If you encounter any issues or have questions:
- Check the User Guide for detailed instructions
- Review the Technical Documentation
- Report bugs on GitHub Issues
- Contact: support@crow-eye.com
Running this across an organization?
SENTINEL · RELEASING SOONThe build above is the free, open-source engine — built for one analyst, on one workstation, one case at a time. Crow-Eye Sentinel is the enterprise tier: the same exhaustive artifact parsing, running continuously across every endpoint you own. That is Continuous Forensic Reconstruction (CFR) at fleet scale — the history is already parsed and correlated before anyone asks the question.
Fleet-wide collection
Distributed agents parse the full artifact set locally, on a schedule — before log rollover or attacker cleanup takes the evidence.
Proactive UBA
Behavioural baselines per identity across the fleet, to surface insider staging before the data ever leaves the network.
Wing Rules & SIEM
Your investigators define the correlation logic, and findings forward into the stack you already run.
For investigators and security teams: Sentinel is pre-release and the Design Partner Program is open — a small group shaping the product before general availability. Requests are read personally.