HIBERNATION RECON

The tools and techniques used for many years to analyze Microsoft Windows® hibernation files have left digital forensics experts in the dark… until now! Hibernation Recon not only supports active memory reconstruction from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files, but also extracts massive volumes of information from the multiple types (and levels) of slack space that often exist within them. Additional features of Hibernation Recon include the automatic recovery of valuable NTFS metadata and parallel processing of multiple hibernation files.

Are you intersted in this product?

1300 55 33 24

contact@cdfs.com.au

Quote Request

HIBERNATION RECON

The tools and techniques used for many years to analyze Microsoft Windows® hibernation files have left digital forensics experts in the dark… until now!

Hibernation Recon not only supports active memory reconstruction from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files, but also extracts massive volumes of information from the multiple types (and levels) of slack space that often exist within them. Additional features of Hibernation Recon include the automatic recovery of valuable NTFS metadata and parallel processing of multiple hibernation files.

Hibernation Recon, along with all other Arsenal Recon tools, is available as part of an affordable monthly subscription – currently, $49 per month. If Hibernation Recon is run without a license, a “Free Mode” is provided which supports the extraction of active contents from both legacy and modern Windows hibernation files. Please contact sales regarding discounts for volume licensing.

  • Hibernation-Recon-1.1.0.55_Beta_Parallel-Processing
  • Hibernation-Recon-1.1.0.53_Beta-Waiting-to-Process-Hibernation-Files
  • Hibernation-Recon-Processing-a-Windows-10-x64
  • Hibernation-Recon-v1-Root-Output-from-Processing-a-Windows-10-x64-Hibernation-File.PNG
  • Hibernation-Recon-v1-RawSlackChunks-Output-from-Processing-a-Windows-10-x64-Hibernation-File
  • Hibernation-Recon-v1-DecompressedSlackLevels-Output-from-Processing-a-Windows-10-x64-Hibernation-File

Active Memory

Reconstruction of active memory from Windows XP, Vista, 7, 8/8.1, and 10 hibernation files

Hibernation Slack

Only tool that properly supports extraction of multiple types and levels of hibernation slack

NTFS Metadata

Automatic recovery of valuable NTFS metadata

Features

  • Windows XP, Vista, 7, 8/8.1, and 10 hibernation file support
  • Active memory reconstruction
  • Identification and extraction of multiple levels of slack space
  • Brute force decompression of partially overwritten slack
  • Segregation of extracted slack based on particular hibernation
  • Proper handling of legacy hibernation data found in modern hibernation files
  • NTFS metadata recovery with human-friendly decoding
  • Parallel processing of multiple hibernation files

Requirements

  • HIBERNATION RECON requires Microsoft Windows 8 or later.
/* Omit closing PHP tag at the end of PHP files to avoid "headers already sent" issues. */