From Forensics Wiki
Revision as of 22:09, 17 April 2013 by Tmyroadctfig
- EnCase, AccessData and raw dd images.
- HFS+, HFSX, ext2/3/4, NTFS, FAT16/32
- Cellebrite and XRY images
- NTFS deleted file recovery and file carving support for all supported file systems.
- Processing the data produces a full text index that can be quickly searched.
- The ability to extract out several types of "named entities" including email addresses, IP addresses, references to companies and currencies.
- It also provides a network graph to see the communications detected inside the data.