Insectra is a Value Added Reseller of X-Ways Forensics. It runs
under Windows 2000/XP/2003/Vista*/2008*/7*. X-Ways Forensics is very efficient to use after a
while, often runs faster, is not as resource-hungry, finds deleted
files and search hits that the competitors will miss, offer many features
that the others lack and it comes at a fraction of the cost!
It is based on the
WinHex
hex and disk editor and part of an efficient
workflow model where computer forensic examiners share data and
collaborate with investigators that use
X-Ways Investigator. X-Ways Forensics comprises all the general and specialist features known from WinHex,
such as:
- Disk cloning and imaging
- Examining the complete directory structure inside raw
(.dd) image files, even
spanned over several segments
- Native support for FAT, NTFS, Ext2/3/4,
CDFS, UDF
- Built-in interpretation of RAID 0 and RAID 5 systems and
dynamic disks
- Complete access to disks, RAIDs, and images more than
2 TB in size (more than 232 sectors)
- Viewing and dumping physical RAM and the
virtual memory of running processes
- Various data recovery techniques and file carving
- File header signature database, based on
flexible GREP notation
- Hard disk cleansing to produce forensically sterile media
- Gathering slack space, free space, inter-partition space, and generic
text from drives and images
- File and directory catalog creation for all computer media
- Easy detection of and access to NTFS alternate data streams (ADS)
- Mass hash calculation for files (CRC32, MD4,
ed2k, MD5, SHA-1, SHA-256, RipeMD, ...)
- Unlike a competing product, does not depend exclusively on MD5 (collisions in MD5)
- Powerful physical and logical search capabilities for many search terms at the
same time
- Recursive view of all existing and deleted files
in all subdirectories
- Automatic coloring for the structure of FILE
records in NTFS
- Bookmarks/annotations
- Bates-numbering files
- ...