ADF Triage-Examiner®

A proven triage solution to reduce and manage backlogs

 

tex boxForensic backlogs are reaching unprecedented levels and are a significant threat facing the digital forensic community today. Experts agree that the most practical and innovative solution is to reduce the number of computers entering the backlog.

Triage-Examiner is the most comprehensive tool available today to filter and qualify cases for full forensic examinations. The tool is complementary to other forensic programs and is fast becoming a must-have for every forensic examiner tool kit.

 

Confidently Discard Computers From Backlogs

Triage-Examiner is a forensically sound tool that is run by forensic examiners directly on suspect computers. This triage can identify and eliminate negative computers with the same degree of confidence as can full forensic examinations. Given that on average three out of four computers processed are negative, Triage-Examiner can eliminate 70% of incoming computers in a fraction of the time and using fewer resources.

discard

Using Triage-Examiner

Prior to running a triage scan, a Search Profile is created that defines what information to collect and what evidence to search for on the suspect computers. The Triage Key is then prepared with the triage application and the Search Profile. The scan is executed on a powered-on (live) or powered-off (boot) computer with the Triage Key. Triage-Examiner utilizes the computer as a review station to display the results in real time.

steps


 

Key Benefits

  • Identify negative computers quickly
  • Provide highest confidence levels
  • Automated and forensically sound process
  • Bypass imaging and indexing processes
  • Reduce number of forensic program licenses required
  • Run multiple triage scans in parallel with a single license key
  • Ability to export triage results to other programs
  • Easy to learn

SearchPak®
Features

  • File collection
  • Keywords
  • Regular expressions
  • Hash values
  • Image signatures
  • Import hash and keyword lists

CapturePak™

  • Installed applications
  • History of attached devices
  • General system information
  • Internet browsing history
  • Internet search history
  • Internet cookies
  • Networking information
  • User profiling information
  • Chat logs
  • State of drive encryption
  • Google Map artifacts
  • Password information
  • Windows encryption keys (live)
  • Dynamic memory (live)
  • Screenshot of all applications (live)
  • Clipboard (live)
  • And more ...

Supported Devices and Systems

  • Live scan of 32-bit and 64-bit versions of Windows XP, Vista, 7, Server 2003, and Server 2008
  • Boot scan of 32-bit and 64-bit Intel compatible computers (Windows, Linux, and Macintosh)
  • FAT, NTFS, EXT2, EXT3, HFS, and HFS+ file systems
  • Removable media (USB and FireWire hard drives, memory cards, etc.)