Ch a p t e r 1 - I n t r o d u c t i o n
13 | Page
Copyright GetData Forensics Pty Ltd 2010 - 2014, All rights reserved.
Macintosh HFS, HFS+ (no journal processing)
EXT 2/3/4 (no journal processing)
CD/DVD ISO, UDF
Hardware and Software RAID: JBOD, RAID 0, RAID 5
KEY PROGRAM FEATURES
Key Forensic Explorer features include:
Fully Customizable Interface: The forensic explorer interface has been designed for
flexibility. Drag, drop and detach windows for a customized module. Save and load
module configurations to suit investigative needs.
International Language Support: Forensic Explorer supports Unicode. Investigators
can search and view data in native language format.
Complete Data Access: Access all areas of physical or imaged media at a file, text, or
hex level. View and analyze system files, file and disk slack, swap files, print files, boot
records, partitions, file allocation tables, unallocated clusters, etc.
Powerful Pascal Scripting language: Automate analysis using a provided script library,
or write your own analysis scripts.
Fully Threaded: Run different analysis functions in separate threads.
Data Views: Powerful data views including:
File List: Sort and multi sort files by attribute, including, extension, signature,
hash, path and created, accessed and modified dates.
Category Views: Show files by extension, date etc.
Disk: Navigate a disk and its structure via a graphical view. Zoom in and out
to graphically map disk usage.
Gallery: Thumbnail photos and image files.
Display: Display more than 300 file types. Zoom, rotate, copy, search.
Filesystem Record: Easily access and interpret FAT and NTFS records.
Text and Hexadecimal: Access and analyse data at a text or hexadecimal.
Automatically decode values with the data inspector.
File Extent: Quickly locate files on disk with start and end sector runs.
Byte Plot and Character Distribution: Examine individual files using Byte Plot
graphs and ASCII Character Distribution.
File Metadata: Examine metadata properties within files.