• Home
  • Products
  • Training
  • Support
  • About Us
  • Forum
  • Sign In

File System Browser

Discover
  • Find files faster
  • Search within files
  • Search for E-mails
  • Recover deleted files
  • Uncover User Activity
  • Collect system information
  • Password recovery
  • Hidden Disk Areas - HPA/DCO
  • Volume Shadow Copy
  • Web Browser
Identify
  • Verify and match files
  • Find misnamed files
  • Compare drive signatures
  • Timeline viewer
  • File viewer
  • Memory viewer
  • Binary String Extraction
  • Email viewer
  • Registry viewer
  • File system browser
  • Raw disk viewer
  • Thumbnail cache viewer
  • SQLite database browser
  • ESE database browser
  • Prefetch viewer
  • $UsnJrnl viewer
  • Plist viewer
  • Event Log Viewer
  • Web Server Log Viewer
Manage
  • Case management
  • Generate reports
  • Storage device management
  • Drive Imaging
  • Cloud Drive Imaging
  • Cloud Account Imaging
  • Rebuild RAID arrays
  • Portability
  • Secure case logging
  • Support

Explorer-like Navigation of supported file systems on physical drives, volumes and imagesOSForensics™ provides an explorer-like File System Browser of all devices that have been added to the case. Unlike Windows Explorer, the File System Browser is able to display additional forensic-specific information, as well as allow analysis to be performed using OSForensics' integrated tools.

Supported file systems are:

  • NTFS (Windows)
  • FAT16 / FAT32 / exFAT (DOS/Windows)
  • Ext2 / Ext3 / Ext4 (Linux/Android)
  • HFS+ / HFSX (Mac/iPhone/iPad)
  • APFS (Mac/iPhone/iPad)

Forensics-related operations can be performed directly on the files/folders, such as hash set lookup, indexing, viewing with built-in file viewer, and adding files to a case.

File System Browser

Other features include

  • Listing deleted files in the current folder.
  • NTFS file permissions are completely bypassed
  • Viewing $I30 slack space file names
  • Displaying NTFS Steams & stream size for each file
  • Showing fragmentation state for each file
  • Viewing hidden system files, such as $Attdef, $BadClus, $Bitmap & $MFT
  • Recursive calculation of directory sizes
  • Precise display of all file system dates / times
Home
Discover Identify Manage
Contact Us Legal Disclaimer
Products
OSForensics OSForensics Bootable (USB Flash Drive) Rainbow Tables - 3TB hard disk
Training
Online Training Course Certification Exam - Online Triage Exam - Online Face-to-Face Classes 2024 Events Calendar
Support
Video Demonstrations FAQs and Tutorials OSForensics Forums Australian Head Office North American Branch

Copyright © 2024 PassMark™ Software