Difference between pages "File Vault" and "Adroit Photo Forensics"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m (New page: File Vault is the cryptographic file system developed by Apple and introduced with MacOS 10.3. File Vault works by storing each user's home directory in an encrypted ".sparseimage" file. ...)
 
(Created page with '{{Infobox_Software | name = Adroit Photo Forensics (APF) | company = Digital Assembly | os = {{Windows}} | genre = {{Analysis}} | license = {{Commercial}} | websi…')
 
Line 1: Line 1:
File Vault is the cryptographic file system developed by Apple and introduced with MacOS 10.3.
+
{{Infobox_Software |
 +
  name = Adroit Photo Forensics (APF) |
 +
  company = [[Digital Assembly]] |
 +
  os = {{Windows}} |
 +
  genre = {{Analysis}} |
 +
  license = {{Commercial}} |
 +
  website = [http://www.digital-assembly.com/products digital-assembly.com] |
 +
}}
  
File Vault works by storing each user's home directory in an encrypted ".sparseimage" file. The file is automatically mounted when the user logs in and unmounted when the user logs out. All of the user's files and preferences are stored in this file.  The file's encryption key is stored in the .sparseimage file, but that encryption key is itself encrypted with the user's login password.  
+
'''Adroit Photo Forensics''' ('''APF''') is a commercial forensic software package distributed by [[Digital Assembly]].
 +
It specializes in the recovery and analysis of digital photographs.
  
There are no known attacks against File Vault other than a brute force attack on the user's password.
+
=Features=
 +
 
 +
Adroit Photo Forensics can parse a number of filesystems, including [[FAT]] 12/16/32, [[NTFS]], [[HFS]], and [[HFS]]. It can
 +
read from [[EnCase]] as well as raw/[[dd]] images.
 +
 
 +
It is best known for implementing the [[File_Carving:SmartCarving|SmartCarving]] and [[File_Carving:SmartCarving|GuidedCarving]]
 +
algorithms to recover fragmented photos.
 +
 
 +
== Exif ==
 +
 
 +
Adroit Photo Forensics also parses exif data and can be used to view and group files based on exif date stamps instead of
 +
file system date stamps. APF also includes a full zoomable time-line viewer based on exif and file system date stamps.
 +
 
 +
== Other Features ==
 +
 
 +
Adroit Photo Forensics interface is optimized for the display of photos. APF also include grouping and sorting options that are
 +
photo relevant.
 +
 
 +
== External Links ==
 +
 
 +
[http://digital-assembly.com/products/adroit-photo-forensics/ Adroit Photo Forensics Product Information]

Revision as of 13:57, 26 October 2009

Adroit Photo Forensics (APF)
Maintainer: {{{maintainer}}}
OS: Windows
Genre: Analysis
License: Commercial
Website: digital-assembly.com

Adroit Photo Forensics (APF) is a commercial forensic software package distributed by Digital Assembly. It specializes in the recovery and analysis of digital photographs.

Features

Adroit Photo Forensics can parse a number of filesystems, including FAT 12/16/32, NTFS, HFS, and HFS. It can read from EnCase as well as raw/dd images.

It is best known for implementing the SmartCarving and GuidedCarving algorithms to recover fragmented photos.

Exif

Adroit Photo Forensics also parses exif data and can be used to view and group files based on exif date stamps instead of file system date stamps. APF also includes a full zoomable time-line viewer based on exif and file system date stamps.

Other Features

Adroit Photo Forensics interface is optimized for the display of photos. APF also include grouping and sorting options that are photo relevant.

External Links

Adroit Photo Forensics Product Information