Forensic Explorer
-
Price$1950
- Website
About Forensic Explorer:
Forensic Explorer can recover, analyze, and report data from both physical storage devices and forensic image files. With a wide array of features, investigators can access and scrutinize data at various levels, from file metadata to system structures. It's equipped with advanced functionalities like data carving, keyword searching, and hash verification, making it efficient for uncovering digital evidence.
Forensic Analysis Software:
Suitable for new or experienced investigators, Forensic Explorer combines a flexible and easy to use GUI with advanced sort, filter, keyword search, data recovery and script technology. Quickly process large volumes of data, automate complex investigation tasks, produce detailed reports and increase productivity. Manage all aspects of the investigation, including:
File System Analysis, Keyword & Index Search, Live Boot Virtualization, Email, Registry, and report
Key Features:
Anti-Virus: Integrated with Cisco Clam anti-virus.
Bookmark: Allows users to bookmark, flag, or categorize potential evidence.
Case Management: Capability to create, save, and load case files.
Data Access: Access and analyze all areas of physical or imaged media at various levels, including system files, swap files, boot records, and more.
Data Carving: Built-in tool to carve over 300 known file types.
Data Views: Offers multiple views like File List, Disk structure, Gallery, Filesystem Record, and more.
Email: Supports various formats like PST, OST, EDB, MBOX with keyword and index search capabilities.
Export: Export files to disk or directly to .L01 forensic evidence files.
GUI: Customizable workspace with detachable views suitable for multiple monitors.
Hash: Apply hash sets to identify or exclude files. Supports MD5, SHA1, SHA256, CRC, and more.
Index: Features built-in DTSearch index capability.
Keyword Search: Enables cluster, sector, or byte-level keyword searches.
Language: Unicode compliant, allowing data search and view in native languages.
Metadata: Extracts and reports file metadata, including EXIF, GPS, and MS Office data.
Mount (MIP): Mount forensic image files as a Windows drive letter.
RAID: Supports various RAID configurations, including software and hardware RAID.
Recovery: Ability to recover deleted folders and partitions.
Registry: Analyze Windows registry hives with filtering, categorization, and automated analysis.
Reporting: Custom report builder with predefined templates.
Scripting: Inbuilt Delphi scripting language with scripts for metadata, registry, and more.
Network Servelet: Examine remote drives using a deployable network servelet.
Shadow Copy: Analyze shadow copy files.
Signature: Verify the signature of every file and identify mismatching file extensions.
Triage: Automated triage and reporting on common forensic search criteria.
Virtual Live Boot: Virtualize Windows and MAC forensic images using VirtualBox or VMWare.
Add a review