Digital Forensics: Empowering Experts On-Scene and in the Lab
ADF forensic tools are the best lightweight, portable digital forensic software devices used worldwide to solve lab and front-line field investigations:
- Mobile Device Investigator® - Mobile Device Investigator® is a mobile forensics triage tool that is user-friendly, requires minimal training, and is designed for front-line law-enforcement, analysts, and forensic examiners.
- Digital Evidence Investigator® - Digital Evidence Investigator® is a computer forensics triage tool designed for front-line law enforcement, analysts, and forensic examiners.
- ADF PRO - ADF PRO software is a full ADF product suite of mobile and computer triage software that is user-friendly and is designed for front-line law-enforcement, analysts, and forensic examiners.
Capabilities and Features
Can the ADF tools be used by non-technical users?
Yes. ADF has been providing easy-to-use yet powerful triage tools for non-technical users since 2005, and we have numerous client success stories.
Are the ADF tools forensically sound?
Yes, this is a key feature of ADF tools. See table below.
Description | Powered-OFF Computers | Powered-ON Computers |
---|---|---|
Forensically sound | Yes | Partically |
Change to file time stamps | No | No |
USB key registry entry in standard mode | No | Yes |
USB key registry entry in stealth mode (Triage-G2 only) | No | No |
What are the ADF capabilities for scanning live (on) computers, dead (off) computers, removed hard drives, and drive images?
Computer/Media | Triage-G2 | DEI | Triage-Investigator |
---|---|---|---|
Live (on) computers | |||
Dead (off) computers | |||
Removed hard drives | |||
External media (CDs, DVDs, SD cards, USB drives, etc.) | |||
Drive images (dd, e01) |
What computer operating systems will ADF tools work on?
ADF tools are designed to scan the following systems:
Powered-off target computer (boot scan)
- Firmware: BIOS, UEFI, SECURE UEFI, MAC EFI 2.0 (released after 2010)
- CPU: Intel 64-bit or compatible
- RAM: 2GB or more
- File sytems: FAT, NTFS, HFS+, EXT2/3/4
- RAID: 0,1,5
- Windows Dynamic Disks: not supported
Powered-on target computers (live scan)
- Windows Vista/7/8/10 64-bit, Server 2008/2012 64-bit
- Windows Dynamic Disks: simple volumes only (no spanned, striped, mirrored, RAID-5, volumes)
Drive image scan from the Desktop application
- Format: dd and e01
- File systems: FAT, NTFS, HFS+, EXT2/3/4
- OS: Windows, Mac, Linux, iOS, Android
- RAID: rebuilding RAID is not supported, so image must represent a logical disk
Folder scan from the Desktop application
- OS: Windows, Mac, Linux, iOS, Android
Can ADF tools scan tablets and smartphones?
Yes, ADF digital forensic capabilities for logical acquisition and analysis include iOS, Android, and ChromeOS platforms.