
- #PRODISCOVER FORENSICS FILE TYPES ARCHIVE#
- #PRODISCOVER FORENSICS FILE TYPES UPGRADE#
- #PRODISCOVER FORENSICS FILE TYPES LICENSE#
Hash individual files for analysis.Ĭluster, sector, or byte level keyword search of entire media using text, regex or hex expressions.įorensic Explorer is Unicode compliant. Save and load personal work-space configurations to suit investigative needs.Īpply hash sets to a case to identify or exclude known files. L01 forensic evidence files.ĭetach drag and drop views for a customized work-space on multiple monitors.
Byte Plot and Character Distribution: Examine individual files using Byte Plot graphs and ASCII character distribution.Įmail support for PST, OST, EDB, MBOX formats. Full keyword and index search capabilities for email.Įxport files to disk, or direct to. File Extent: Quickly locate the location of files on disk with start and end sector runs. Automatically decode values with the data inspector. Text and Hexadecimal: Access and analyze data at a text or hexadecimal. Filesystem Record: Easily access and interpret FAT and NTFS records. Display: Display more than 300 file types. Gallery: Thumbnail photos and image files. Zoom in and out to graphically map disk usage. Disk: Navigate a disk and its structure via a graphical view. File List: Sort and multiple sort files by attribute, including, extension, signature, hash, path and created, accessed and modified dates. Inbuilt data carving tool to carve more than 300 known file types. View and analyze system files, file and disk slack, swap files, print files, boot records, partitions, file allocation tables, unallocated clusters, etc. #PRODISCOVER FORENSICS FILE TYPES UPGRADE#
No major version upgrade costs (valid maintenance give access to the latest build).īookmark, flag, or categorize potential evidence.Īccess all areas of physical or imaged media at a file, text, or hex level. #PRODISCOVER FORENSICS FILE TYPES LICENSE#
Forensic Explorer includes a stand-alone license of Mount Image Pro. Trid is unusable without the database.Key Features forensic-explorer-facts-sheet (English) The last part of the version represents the release date of the trid database. If you have special file formats that only you use, you can also add them to your local database, making their identification easier. Other people around the world will be doing the same thing making the database a dynamic and living thing. As new file types become available you can run the scan module against them and help keep the program up to date. The program will do the rest.īecause TrID uses an expandable database it will never be out of date. Just run the TrIDScan module against a number of files of a given type. See the TrIDScan page for information about how you can help. You can help! Use the program to both recognize unknown file types and develop new definitions that can be added to the library. The database of definitions is constantly expanding the more that are available, the more accurate an analysis of an unknown file can be. #PRODISCOVER FORENSICS FILE TYPES ARCHIVE#
Just download both TrID and this archive and unpack in the same folder. As this is subject to very frequent update, it's made available as a separate package. TrID uses a database of definitions which describe recurring patterns for supported file types. TrID has many uses: identify what kind of file was sent to you via e-mail, aid in forensic analysis, support in file recovery, etc. Instead, it's extensible and can be trained to recognize new formats in a fast and automatic way. While there are similar utilities with hard coded logic, TrID has no fixed rules. TrID is an utility designed to identify file types from their binary signatures.