Timeline viewer provides a visual representation of system activity over timeįile viewer that can display streams, hex, text, images and meta dataĮmail viewer that can display messages directly from the archive Verify and match files with MD5, SHA-1 and SHA-256 hashesįind misnamed files where the contents don’t match their extensionĬreate and compare drive signatures to identify differences Password recovery from web browsers, decryption of office documentsĭiscover and reveal hidden areas in your hard diskīrowse Volume Shadow copies to see past versions of files Uncover recent activity of website visits, downloads and logins Search through email archives from Outlook, ThunderBird, Mozilla and more Search within file contents using the Zoom search engine OSForensics comes with a built-in file viewer which lets you examine a file contents, properties and meta-data, as well as an e-mail viewer which is compatible with most popular mail client formats.įind files faster, search by filename, size and time You can even recover data and files that have been deleted by users. OSForensics can build and let you view an events timeline which shows you the context and time of activities. OSForensics has a number of unique features which make the discovery of relevant forensic data even faster, such as high-performance deep file searching and indexing, e-mail and e-mail archive searching and the ability to analyze recent system activity and active memory. For documents, this would contain Author, Subject, etc.OSForensics Portable is a new digital investigation tool which lets you extract forensic data or uncover hidden information from computers. For image files, this would include Camera make, Model, etc. Meta dataĭisplays the meta data specific to the recognized file format. Show the file attributes of the data stream: Location, Size, Size on disk, recognized file type, creation/modified/accessed dates, and any other file attributes (archive, compressed, read-only, system, hidden, symbolic link). Of course, it is also used to view natural text file formats, such as. ThisĬan allow you to find hidden text within a binary file format. Note that any file format can be viewed as text, including binary files and image files. The text viewer displays the data stream as text. You can also search within the Hex View and String List. (with user configurable string extraction settings specifying minimum and maximum string length, repeating character limit and more). It can extract all ASCII/Unicode text strings contained in the stream The hex/string viewer displays the data stream as raw bytes in hexadecimal. Hex/String Viewer (Binary String Extraction) The following image formats are supported: MPG, MPEG, MP4, AVI, MOV, M4V, MKV, OGV, WMV, RMV, RMVB, FLV, DIVX, and more. The video viewer plays video content and allows for quick inspection by displaying 9 still frames. The following image formats are supported: BMP (Bitmap), JPG (JPEG), GIF, PNG, Exif and TIFF. The image viewer attempts to view the data stream as an image. The viewer consists of several modes that aids specifically with forensic data analysis. OSForensics™ includes a built-in file viewer for analyzing the contents of files, deleted files, memory sections and raw sectors.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |