OSForensics™ allows the user to view and analyze the raw sectors of all physical disks and partitions (including mounted images) attached to the system. This module provides the ability to perform a deeper inspection of a drive, looking beyond the data stored in the file system's files and directories. Performing this level of analysis may be required if information of interest is suspected to be hidden within the raw sectors of the drive, which are not normally accessible via normal operating system mechanisms (eg. free clusters, file slack space).
The Raw Disk Viewer includes features specifically for forensics analysis such as text/hex searching, highlighting of relevant disk offsets, and decoding of known disk structures (such as MBR, GPT)