SOLVE INVESTIGATIONS FAST!
Our newest release of ADF Software is designed for investigators and lab examiners who want to reduce forensic backlogs. ADF tools have a proven track record of automating the forensically sound collection, analysis and reporting on digital evidence.
ADF software is easy-to-use and deploy to investigators. You can choose to use the pre-configured scans or build your own custom scans to support your specific investigative needs.
NEW FEATURE HIGHLIGHTS
The new features of the ADF platform are designed to further enhance the capabilities of investigators and lab examiners and include:
- Additional artifact and file collection capabilities including anti-forensic tools and saved credentials
- Ability to investigate live powered on computers, boot scans from powered off computers, forensic images, the contents of folders and network shares (including shares made available by NAS devices)
- Automatic linking of files with artifacts, and time zone detection with the ability view records in a single view
- Additional file system processes: ExFAT and YAFFS2
- Decrypt and scan/image BitLocker volumes including those using new AES-XTS encryption algorithm introduced in Windows 10
ADF PLATFORM FEATURES
- Highly configurable artifact and file collection including social media, P2P, bitcoin, cloud storage, user login events, anti-forensic tools, saved credentials and files shared via Skype
- Able to investigate live powered on computers, dead powered off computers, forensic images, the contents of folders and network shares (including shares made available by NAS devices)
- Rapidly search suspect media using large hash sets (>30 million), including Project VIC and CAID
- Automatic tagging of hash and keyword matches, linking of files with artifacts, and time zone detection
- Powerful keyword and regular expression search capability to find relevant files and artifacts
- Search and collect emails including Windows Mail 10
- Ability to define new file types and select individual ones to be processed
- Display provenance, including comprehensive metadata, of all relevant files and artifacts
- Comprehensive video preview and frame extraction
- Recover images from unallocated drive space
- A unique timeline that combines files and artifact records, with a user’s actions into a single view
- Process NTFS, FAT, HFS+, EXT, ExFAT and YAFFS2 file systems
- Powerful reporting capabilities (HTML and CSV)
- Portable standalone viewer to easily share results with others (i.e., prosecutors or other investigators)
- Out-of-the-box imaging capabilities
- 64-bit architecture delivers high performance and scalability
- Powerful booting capability (including UEFI secure boot and Macs) provides access to internal storage that cannot easily be removed from computers
- Ram Capture capability
- Detect and warn of BitLocker and FileVault2 protected drives
- Decrypt and scan or image BitLocker volumes including those using the new AES-XTS encryption algorithm introduced in Windows 10
- Collect protected and corrupted files for later review