What is X-Way Forensics?
X-Ways Forensics is an advanced work software for computer forensic examiners. Compared to its competitors, X-Ways Forensics is more efficient because it consumes fewer resources, usually runs faster, finds deleted files, offers much more features, is more reliable in performance, comes with a low cost, has no absurd hardware requirements, does not depend on a complex and extensive database and among other functions.
X-Ways Forensics is also portable, you can run it on a USB stick on any system if you want. And because Forensics is based on WinHex's hexadecimal and disk editor, it is part of an efficient workflow model in which computer forensic examiners share their data with researchers using X-Investigator Ways.
X-Ways Forensics comprises all known general and specialized features of WinHex, as an example:
- Disk and image cloning
- Reading partitioning structures and file system within RAW image files, ISSO, VHD, and VMDK
- Full access to disks, RAIDs, and images over 2TB in size with a sector size of up to 8KB
- Internal interpretation of JBOD, RAID 0, RAID 5, RAID 5EE and RAID 6 systems, Linux software RAIDs, Windows dynamic disks, and LVM2
- Automatic identification of lost/deleted partitions
- Suporte nativo para FAT12, FAT16, FAT43, exFAT, TFAT, NTFS, Ext2, Ext4, Next3, CDFS, ISO9660, Joliet e UDF
- Superposition of sectors, such as corrected partition tables or file system data structures for analysis of file systems completely, despite data corruption, without changing the disk or the original image
- Access to logical memory of running processes
- Various data recovery techniques, fast and powerful file recording
- Well-maintained file header signature database based on GREP annotation
- Data interpreter, knowing 20 types of variables
- Visualization and editing of binary data structures using models
- Hard drive cleaning for sterile forensic media production
- Collection of slack space, free space, space between partitions, and generic text from drives and images
- Creating file catalog and directories for all computer media
- Easy detection and access to NTFS (ADS) alternative data streams
- Bulk hash calculation for files (Adler32, CRC32, MD4, MD2, MD5, SHA-1, SHA-256, RipeMD-128, RipeMD-160, Tiger-128, Tiger-16, Tiger-192, TigerTree and etc.)
- Powerful fast and lightning powerful physical and logic search capability for many search terms at the same time
- Recursive view of all existing and deleted files in all subdirectories
- Automatic coloring for the FILE and NTFS record structure
- Favorites and annotations
- Runs on Windows FE, the Windows environment that is compatible with forensics, as an example, for sorting and viewing, with limitations
System requirements:
- Windows XP, 2003, Vista, 2008, 7, 8, 8.1, 2012 and 10 of 32 or 64bits
- Linux + Wine. However, with Linux, some functions will be limited, as the software has not been completely programmed for Linux