Digital Forensics: Empowering Experts On-Scene and in the Lab

ADF makes the leading digital forensic software for lab examiners and field investigators.  Our products are easy-to-use and learn and include: 

Request a Demo

Capabilities and Features

What are the differences between Triage-Investigator and DEI?

Both Digital Evidence Investigator® (DEI) and Triage-Investigator scan suspect computers using ADF Search Profiles. However, Triage-Investigator can only use the default Search Profiles shipped with the software OR custom profiles created in DEI, whereas with DEI you can create custom Search Profiles.
Each copy of Triage-Investigator DOES NOT NEED a corresponding copy of DEI to setup custom Search Profiles. However, agencies should have at least one copy of DEI to provide custom Search Profiles to all Triage-Investigator installations at the same agency. Without this, Triage-Investigator users will be limited to only the default Search Profiles shipped with the software. For details on the default Search Profiles, please contact support@adfsolutions.com.
View a complete ADF Product feature comparison

Can the ADF tools be used by non-technical users?

Yes. ADF has been providing easy-to-use yet powerful triage tools for non-technical users since 2005, and we have numerous client success stories.

Are the ADF tools forensically sound?

Yes, this is a key feature of ADF tools. See table below.
Description Powered-OFF Computers Powered-ON Computers
Forensically sound Yes Partically
Change to file time stamps No No
USB key registry entry in standard mode No Yes
USB key registry entry in stealth mode (Triage-G2 only) No No

What are the key differences among the ADF tools?

All ADF forensic tools share the same search and scan engine. The differences are aimed at 1) usage scenarios – specifically military operations, forensic lab examination, and field investigations, and 2) user risk management.

Triage-G2® has been designed to meet military media exploitation requirements. The tool is primarily used by operators who have training to both run the tool (basic mode) and with additional training, the option to configure the tool (advanced mode). It also offers a stealth mode for live scans, advanced search configurations, and an integrated authentication and collection key for optimized workflow. It is however limited to scanning a single computer at one time.

Digital Evidence Investigator® (DEI) has been designed to meet both forensic lab and field triage requirements. It is primarily used by both forensic examiners and investigators who have training to run and configure the tool (advanced mode only). It also offers advanced search configurations, and separate authentication and collection keys which allows users to scan multiple computers simultaneously. It does not offer stealth mode during live scans or the ability to switch to basic user mode.

Triage-Investigator® has been designed for field triage requirements. It is primarily used by investigators with limited digital forensic training in running the tool (basic mode only). This basic user mode allows for ease of use and limits user risk. It also offers a separate authentication and collection keys which allows users to scan multiple computers simultaneously. It does not offer stealth mode during live scans, advanced search configurations, or the ability to switch to advanced mode.

See our ADF forensic tool comparison page here: ADF Product feature comparison

What are the ADF capabilities for scanning live (on) computers, dead (off) computers, removed hard drives, and drive images?

Computer/Media Triage-G2 DEI Triage-Investigator
Live (on) computers      
Dead (off) computers      
Removed hard drives      
External media (CDs, DVDs, SD cards, USB drives, etc.)      
Drive images (dd, e01)      

What computer operating systems will ADF tools work on?

ADF tools are designed to scan the following systems:

Powered-off target computer (boot scan)

  • Firmware: BIOS, UEFI, SECURE UEFI, MAC EFI 2.0 (released after 2010)
  • CPU: Intel 64-bit or compatible
  • RAM: 2GB or more
  • File sytems: FAT, NTFS, HFS+, EXT2/3/4
  • RAID: 0,1,5
  • Windows Dynamic Disks: not supported

Powered-on target computers (live scan)

  • Windows Vista/7/8/10 32/64-bit, Server 2008/2012 32/64-bit
  • Windows Dynamic Disks: simple volumes only (no spanned, striped, mirrored, RAID-5, volumes)

Drive image scan from the Desktop application

  • Format: dd and e01
  • File systems: FAT, NTFS, HFS+, EXT2/3/4
  • OS: Windows, Mac, Linux, iOS, Android
  • RAID: rebuilding RAID is not supported, so image must represent a logical disk

Folder scan from the Desktop application

  • OS: Windows, Mac, Linux, iOS, Android

Can ADF tools scan tablets and smartphones?

ADF digital forensic capabilities for logical acquisition and analysis of iOS and Android platforms are currently in Beta and are scheduled for release soon.  Please contact us if you are a customer and would like to participate in the ADF "Smartphone Beta".