X-Ways Forensics
A powerful digital forensics tool for data extraction, search, and analysis, widely used in legal investigations and electronic evidence analysis
X-Ways Forensics UI

X-Ways Forensics

  • Work more efficiently, run faster.
  • Powerful data search capabilities.

No installation needed; it can be run directly from a USB drive on Windows operating systems. Its portability and one-click execution make it ideal for on-site use.

Description
  • Supports file system types including FAT12/FAT16/FAT32, exFAT, NTFS, Ext2/Ext3/Ext4, CDFS/ISO9660/Joliet, UDF, HFS, HFS+, UFS, APFS.
  • An analyzes complete directory structures in RAW/dd/ISO/VHD/VMDK format forensic images, supporting segmented image files.
  • Supports parsing disk arrays such as JBOD, RAID 0, RAID 5, RAID 6, Linux arrays, Windows dynamic disks, and LVM2 logical volume manager.
  • Highly portable, can be run directly from a USB drive without installation.
  • Powerful keyword search functionality in both English and Chinese, allowing simultaneous multi-keyword searches and successful compound file searches.
  • Strong data recovery capabilities, with file carving based on file signatures.
  • Includes hash analysis to identify inconsistencies between file extensions and signatures.
  • Supports various hash calculation methods (CRC32, MD4, ed2k, MD5, SHA-1, SHA-256, RipeMD, etc.).
  • Capable of analyzing the Windows USN Journal ($UsnJrnl).
  • Supports .e01 format forensic images, with optional 256-bit AES encryption for image files.