All Supported File Systems, no network capabilities (single user license)
Computer Forensic Tool for Law Enforcement ProDiscover™ Forensics is a powerful computer security tool that enables computer professionals to find all the data on a computer disk while protecting evidence and creating evidentiary quality reports for use in legal proceedings.
ProDiscover Forensics edition provides all the capabilities as ProDiscover for Windows and also includes all additionally supported file systems such as SUN Solaris UFS.
Features and Benefits:
Create Bit-Stream copy of disk to be analyzed, including hidden HPA section (patent pending), to keep original evidence safe.
Search files or entire disk including slack space, HPA section, and Windows NT/2000/XP Alternate Data Streams for complete disk forensic analysis.
Preview all files, even if hidden or deleted, without altering data on disk, including file Metadata.
Maintain multi-tool compatibility by reading and writing images in the pervasive UNIX™ dd format.
Examine and cross reference data at the file or cluster level to insure nothing is hidden, even in slack space.
Automatically generate and record MD5 or SHA1 hashes to prove data integrity.
Utilize user provided or National Drug Intelligence Center Hashkeeper database information to positively identify files.
Examine FAT12, FAT16, FAT 32 and all NTFS file systems including Dynamic Disk and Software RAID for maximum flexibility.
Examine Sun Solaris UFS and Linux Ext 2/3 file systems.
Integrated graphics thumbnail viewer and registry viewer.
Extracts EXIF information from JPEG files to identify file creators.
Automated report generation in XML format saves time, improves accuracy and compatibility.
GUI interface and integrated help function assure quick start and ease of use.
Designed to NIST Disk Imaging Tool Specification 3.1.6 to insure high quality.
ProDiscover™ Forensics is a key tool for effective computer forensic analysis. It is not possible to hide data from ProDiscover™ Forensics as it reads the disk at the sector level. This least intrusive approach also allows you to examine the files without altering any valuable metadata such as last time accessed. ProDiscover Forensics will not alter any data on the disk - period! ProDiscover™ Forensics can recover deleted files, examine slack space and access Windows Alternate Data Streams. It can even dynamically allow you to preview, search and image the Hardware Protected Area (HPA) of the disk utilizing a patent pending process.
ProDiscover™ Forensics lets you search through the entire disk for keywords and phrases with full Boolean search capability to find the data you want. You can use the hash comparison capability to find known illegal files or to weed out known good files such as standard operating system files by utilizing the included data from National Drug Intelligence Center in their Hashkeeper database. ProDiscover™ Forensics's powerful search capability is fast and flexible, allowing you to search for words or phrases anywhere on the disk, including the slack space. The extensive on-line help capability and easy to use GUI interface allow you to quickly start using ProDiscover™ Forensics.
ProDiscover™ Forensics automatically creates evidentiary quality reports needed to document your results, complete with every file and hash signature where evidence was found. This saves time and prevents errors which might compromise your case.
System Requirements:
Windows 98SE/NT/2000/2003/XP
800 MHz or higher Pentium-compatible CPU
256 MB RAM (512 MB recommended)
25 MB available hard-disc space
CD-ROM or DVD-ROM drive
VGA or higher resolution monitor
Keyboard and Mouse (or compatible pointing device)
License: Each single end-user license purchased of ProDiscover™ entitles a single user the right to use the ProDiscover™ software. Copies of ProDiscover™ may be installed on up to three machines provided, however, that only one copy is in use at any given time. ProDiscover™ installations may also be moved as needed. See the ProDiscover™ End-User License Agreement for details. Site and Enterprise licenses are also available for ProDiscover™.
The following are the purchasing options for ProDiscover Forensics - (ALL Supported File Systems) - No Network Capabilities (Single User License). If you require a formal quote, choose one or more products and click on the ""Create an Online Quote"" link at the bottom.
Relevant Products
Customers who bought ProDiscover Forensics - (ALL Supported File Systems) - No Network Capabilities (Single User License) also looked for these solutions from LOGON :-
How to buy ProDiscover Forensics - (ALL Supported File Systems) - No Network Capabilities (Single User License) ?
If you wish to buy ProDiscover Forensics - (ALL Supported File Systems) - No Network Capabilities (Single User License), you can first generate a quote online or request one via email. Send email to sales@logon-int.com.
If the information presented above on ProDiscover Forensics - (ALL Supported File Systems) - No Network Capabilities (Single User License) does not answer all your questions, please Click here.