Difference between revisions of "Disk Explorer"

From Forensics Wiki
Jump to: navigation, search
 
 
(5 intermediate revisions by one user not shown)
Line 1: Line 1:
DiskExplorer is a forensic tool that can be used by investigators to analyze file systems. As of now , the file systems supported by DiskExplorer are: <br>
+
{{Wikify}}
<ul><li>FAT12</li>  
+
 
<li>FAT16</li>
+
DiskExplorer is a forensic tool that can be used by investigators to analyze file systems. The file systems supported by DiskExplorer are: <br>
<li>FAT32 </li>
+
<ul>
<li>NTFS </li></ul>
+
<li>
 +
FAT12</li>  
 +
<li>
 +
FAT16</li>
 +
<li>
 +
FAT32</li>
 +
<li>
 +
NTFS</li>
 +
</ul>
 +
 
 +
DiskExplorer for FAT file systems can accomplish the following tasks[http://www.runtime.org/diskexpl.htm]:
 +
<ul>
 +
<li>
 +
Navigate through your drive by using browser-style back and forth arrows, by going directly to the partition table, boot record, FAT or root directory, by jumping to a certain sector etc.</li>
 +
<li>
 +
Switch between several views, such as hex, text, directory, FAT, partition table and boot record view</li>
 +
<li>
 +
Search your drive for text, boot records, partition tables and sub directories</li>
 +
<li>
 +
Investigate the volume' s boot record by looking at the volume information</li>
 +
<li>
 +
Edit your drive by using the direct read/write mode (not recommended) or the virtual write mode</li>
 +
<li>View and recover even deleted files</li>
 +
<li>Create a virtual volume when your boot record is lost or corrupted</li>
 +
<li>Conduct your own data recovery by taking advantage of all these features</li>
 +
</ul>
 +
DiskExplorer for NTFS file systems can accomplish the following tasks[http://www.runtime.org/diskexpl.htm]:
 +
<ul>
 +
<li>
 +
Navigate through your NTFS drive by jumping to the partition table, boot record, Master file table or the root directory</li>
 +
<li>
 +
Choose between views such as hex, text, index allocation, MFT, boot record, partition table</li>
 +
<li>
 +
Inspect the file entry details, NT attributes etc.</li>
 +
<li>
 +
Search your drive for text, partition tables, boot records, MFT entries, index buffers</li>
 +
<li>
 +
View files</li>
 +
<li>
 +
Save files or whole directories from anywhere on the drive</li>
 +
<li>
 +
Identify the file a certain cluster belongs to</li>
 +
<li>
 +
Create a virtual volume when the boot record is lost or corrupt</li>
 +
<li>
 +
Edit your drive by using the direct read/write mode (not recommended) or the virtual write mode</li>
 +
<li>
 +
Conduct your own data recovery by taking advantage of all these features</li>
 +
</ul>
 +
 
 +
== External Links ==
 +
* [http://www.runtime.org/diskexpl.htm Official website]

Latest revision as of 20:29, 20 April 2007

40px-Ambox warning pn.png

This article, and others, needs to be wikified.
Please remove this template after wikifying.

DiskExplorer is a forensic tool that can be used by investigators to analyze file systems. The file systems supported by DiskExplorer are:

  • FAT12
  • FAT16
  • FAT32
  • NTFS

DiskExplorer for FAT file systems can accomplish the following tasks[1]:

  • Navigate through your drive by using browser-style back and forth arrows, by going directly to the partition table, boot record, FAT or root directory, by jumping to a certain sector etc.
  • Switch between several views, such as hex, text, directory, FAT, partition table and boot record view
  • Search your drive for text, boot records, partition tables and sub directories
  • Investigate the volume' s boot record by looking at the volume information
  • Edit your drive by using the direct read/write mode (not recommended) or the virtual write mode
  • View and recover even deleted files
  • Create a virtual volume when your boot record is lost or corrupted
  • Conduct your own data recovery by taking advantage of all these features

DiskExplorer for NTFS file systems can accomplish the following tasks[2]:

  • Navigate through your NTFS drive by jumping to the partition table, boot record, Master file table or the root directory
  • Choose between views such as hex, text, index allocation, MFT, boot record, partition table
  • Inspect the file entry details, NT attributes etc.
  • Search your drive for text, partition tables, boot records, MFT entries, index buffers
  • View files
  • Save files or whole directories from anywhere on the drive
  • Identify the file a certain cluster belongs to
  • Create a virtual volume when the boot record is lost or corrupt
  • Edit your drive by using the direct read/write mode (not recommended) or the virtual write mode
  • Conduct your own data recovery by taking advantage of all these features

External Links