filmov
tv
Analyse the raw sectors of all devices with OSForensics

Показать описание
OSForensics lets you extract forensic evidence from computers quickly with high performance file searches and indexing. Identify suspicious files and activity with hash matching, drive signature comparisons, e-mails, memory and binary data. Manage your digital investigation and create reports from collected forensic data.
The Raw Disk Viewer module allows the user to analyse the raw sectors of all devices added to the case, along with all physical disks and partitions (including mounted images) attached to the system. This module provides the ability to perform a deeper inspection of a drive, looking beyond the data stored in the file system's files and directories. Performing this level of analysis may be required if information of interest is suspected to be hidden within the raw sectors of the drive, which are not normally accessible via normal operating system mechanisms (eg. free clusters, file slack space).
The Raw Disk Viewer module allows the user to analyse the raw sectors of all devices added to the case, along with all physical disks and partitions (including mounted images) attached to the system. This module provides the ability to perform a deeper inspection of a drive, looking beyond the data stored in the file system's files and directories. Performing this level of analysis may be required if information of interest is suspected to be hidden within the raw sectors of the drive, which are not normally accessible via normal operating system mechanisms (eg. free clusters, file slack space).