HIBERNATION RECON

The exploitation of Windows hibernation files to “look back in time” and uncover compelling evidence is crucial to digital forensics practitioners. Hibernation Recon not only supports active memory reconstruction from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files, but also extracts massive volumes of information from the multiple types (and levels) of slack space that often exist within them.

Are you interested in this product?

1300 55 33 24

contact@cdfs.com.au

Quote Request

HIBERNATION RECON

 

The exploitation of Windows hibernation files to “look back in time” and uncover compelling evidence is crucial to digital forensics practitioners. Hibernation Recon not only supports active memory reconstruction from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files, but also extracts massive volumes of information from the multiple types (and levels) of slack space that often exist within them. Additional features of Hibernation Recon include the automatic recovery of valuable NTFS metadata and parallel processing of multiple hibernation files. Digital forensics practitioners cannot afford to analyze electronic evidence without extracting maximum value from Windows hibernation files.

 

If Hibernation Recon is run without a license, it will run in “Free Mode” and provide core functionality. If Hibernation Recon is licensed, it will run in “Professional Mode” with full functionality enabled. More information can be found in Arsenal Recon’s FAQ.

 

  • Hibernation-Recon-1.1.0.55_Beta_Parallel-Processing
  • Hibernation-Recon-1.1.0.53_Beta-Waiting-to-Process-Hibernation-Files
  • Hibernation-Recon-Processing-a-Windows-10-x64
  • Hibernation-Recon-v1-Root-Output-from-Processing-a-Windows-10-x64-Hibernation-File.PNG
  • Hibernation-Recon-v1-RawSlackChunks-Output-from-Processing-a-Windows-10-x64-Hibernation-File
  • Hibernation-Recon-v1-DecompressedSlackLevels-Output-from-Processing-a-Windows-10-x64-Hibernation-File

 

 

Active Memory

 

Reconstruction of active memory from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files

 

Hibernation Slack

 

Only tool that properly supports extraction of multiple types and levels of hibernation slack

 

NTFS Metadata

 

Automatic recovery of valuable NTFS metadata

 

Features

  • Windows XP, Vista, 7, 8/8.1, and 10 hibernation file support
  • Active memory reconstruction
  • Identification and extraction of multiple levels of slack space
  • Brute force decompression of partially overwritten slack
  • Segregation of extracted slack based on particular hibernation
  • Proper handling of legacy hibernation data found in modern hibernation files
  • NTFS metadata recovery with human-friendly decoding
  • Parallel processing of multiple hibernation files

Requirements

  • HIBERNATION RECON requires Microsoft Windows 8 or later.