
X-Ways Forensics
- Work more efficiently, run faster.
- Powerful data search capabilities.
No installation needed; it can be run directly from a USB drive on Windows operating systems. Its portability and one-click execution make it ideal for on-site use.
Description
- Supports file system types including FAT12/FAT16/FAT32, exFAT, NTFS, Ext2/Ext3/Ext4, CDFS/ISO9660/Joliet, UDF, HFS, HFS+, UFS, APFS.
- An analyzes complete directory structures in RAW/dd/ISO/VHD/VMDK format forensic images, supporting segmented image files.
- Supports parsing disk arrays such as JBOD, RAID 0, RAID 5, RAID 6, Linux arrays, Windows dynamic disks, and LVM2 logical volume manager.
- Highly portable, can be run directly from a USB drive without installation.
- Powerful keyword search functionality in both English and Chinese, allowing simultaneous multi-keyword searches and successful compound file searches.
- Strong data recovery capabilities, with file carving based on file signatures.
- Includes hash analysis to identify inconsistencies between file extensions and signatures.
- Supports various hash calculation methods (CRC32, MD4, ed2k, MD5, SHA-1, SHA-256, RipeMD, etc.).
- Capable of analyzing the Windows USN Journal ($UsnJrnl).
- Supports .e01 format forensic images, with optional 256-bit AES encryption for image files.