Tuesday, July 28, 2009

P2 eXplorer v2.0 – Free utility to easily mount and explore forensic HD images (dd, FTK, EnCase, SafeBack, etc)

Paraben Forensics - P2 eXplorer v2.0

“…

Paraben's P2 eXplorer allows you to mount your forensic image and explore it as though it were a drive on your machine while preserving the forensic nature of your evidence. In fact, P2 eXplorer is one of the only programs that mounts images as logical and physical disks. This means all the deleted, slack, and unallocated space is accessible. An image isn't just mounted to view logical files; it is mounted as an actual bit-stream image, preserving unallocated, slack, and deleted data. P2X is easy to use and most importantly, it's free to registered users.

FEATURES:

  • Mounts images as physical disks
  • Mounts Paraben's Forensic Replicator images (PFR)
  • Mounts compressed & encrypted PFR images
  • Mounts EnCase images (up to v6)
  • Mounts SafeBack 1, 2 and 3 images
  • Mounts SMART images
  • Mounts FTK DD and Encase images
  • Mounts WinImage non-compressed images
  • Mounts RAW images from Linux DD & other tools
  • Supports Dynamic drive images
  • Auto-detects image format
  • Supports both logical and physical images types

…”

Not a utility you might usually see me mention, but it’s one of those, if you need it you need it (and I know I’ll need this in the future… so… ;)

(via EDD Update - Free E-Discovery Tools that May Be Worth a Bundle)

No comments: