Designed for forensic examiners and trained investigators in law enforcement & government, as well as IT security personnel in corporations who are conducting full forensic examinations.
- Windows and Mac OSX file system support
- Primarily used in a forensic lab environment
- Native image support for E01, Ex01, L01, Lx01, dd and dmg format
- Search live and deleted artifacts on hard drive and live RAM captures
Powerful Search Capabilities: Search 220+ Internet artifacts and recover more data from more locations.
- Recover data from social networking communications, instant messenger chats, cloud-based artifacts, P2P file sharing apps, mobile backups, webmail, web browser history, pictures and videos
- Proprietary carving technique recovers more data from unallocated space & RAM
- Searches entire logical or physical drives: E01,Ex01,L01,Lx01 and dd images
- Searches Files including the pagefile.sys, hiberfil.sys, and more
- Ability to search multiple drives, images, file & folders in a single search
Find Evidence Quickly: Get immediate search results so you can start working with the data right away.
- Use “Quick Search” preset to see what’s there and focus the investigation
- Review results in real-time without having to wait for search to complete
- Target search by artifact type, keyword and location on hard drive
- Refine search results by skin tone & body part detection
- Multi-threaded support for multi-core processors improving search speed
Standardized Reporting: Flexible reporting and categorization to narrow down evidence quickly.
- Rebuild web pages in their original format on the date they were visited
- Parsed search queries for user keyword searches on major search engines
- Web history categorization (i.e. dating, cloud, classified, chat and social media sites)
- Search, filter, and bookmark important evidence
- Export report in html, pdf, excel, csv, and tab-delimited formats
- Share “Portable Case Folder” with other investigators and stakeholders
- View results in a visual graphical timeline format
Simple to Use: Get to key evidence with only 3 clicks of the mouse.
- Single search for over 200 Internet artifacts. No need to run multiple scripts.
- No need to run multiple scripts.
- Start working on your case immediately. No complicated setup.
- Just “set it” and “forget it” while you work on other things
- No extensive training needed