Digital Shield Inc.

Products
Digital Forensic Software Solution

Forensic Explorer

Forensic Explorer is a tool for the preservation, analysis and presentation of electronic evidence. Primary users of this software are law enforcement, government, military and corporate investigations agencies.

For an official quote for pricing and bundles

Forensic Explorer combines a flexible graphic user interface (GUI) with advanced sorting, filtering, keyword searching, previewing and scripting technology. It enables investigators to:

For an official quote for pricing and bundles

Recommended Requirements

Supported File Formats

Forensics Explorer supports the analysis of the following file formats:

Supported File Systems

Forensic Explorer supports analysis of:

Email Analysis Formats

Email module supports the analysis of .PST files.
The Index Search module (DTSearch) supports the index and keyword search of .PST files.

Key Features

Live Boot: Boot forensic image files. Learn more about Live Boot.

Shadow Copy Analysis: Easily add and analyze shadow copy files. Learn more about Forensic Explorer Shadow Copy Volumes.

Customizable Interface: The forensic explorer interface has been designed for flexibility. Simply drag, drop and detach windows for a customized workspace. Save and load your own workspace configurations to suit investigative needs.
International Language Support: Forensic Explorer is Unicode compliant. Investigators can search and view data in native language format such as Dutch or Arabic.
Complete Data Access: Access all areas of physical or imaged media at a file, text, or hex level. View and analyze system files, file and disk slack, swap files, print files, boot records, partitions, file allocation tables, unallocated clusters, etc.
Fully Threaded Application: Run multiple functions and scripts in threads.
Multiple Core Processing: Maximize PC processors for intensive functions like keyword searching, data carving, hashing, signature analysis.
Powerful Pascal Scripting Language: Automate analysis using a provided script library, or write your own analysis scripts. Automate tasks such as:
Data Views: Powerful data views including:
Categorize and Custom Filter
RAID Support: Work with physical or forensically imaged RAID media, including software and hardware RAID, JBOD, RAID 0 and RAID 5.
Hashing: Apply hash sets to a case to identify or exclude known files. Hash individual files for analysis.
Keyword Search: Sector level keyword search of entire media using RegEx expressions.
Keyword Index: Built in DTSearch index and keyword search technology.
Bookmarks and Reporting: Add case notes to identify evidence and include case notes in a custom report builder.
Data Recovery and Carving: Recover folders, files and partitions. Use an inbuilt data carving tool to carve more than 300 known file types or script your own. Learn more about Forensic Explorer data carving.
Registry Analysis: Open and examine Windows registry hives. Filter, categorize and keyword search registry keys. Automate registry analysis with RegEx scripts.
Scroll to Top