Belkasoft Forensic Carver 1.01

Belkasoft Forensic Carver allows for retrieving deleted information from hard drives and analyzing Live RAM in memory dumps. It helps you to search for various artifacts of a user's online activities like chatting, surfing, emailing.

Belkasoft Forensic Carver 1.01

Belkasoft Forensic Carver allows for retrieving deleted information from hard drives and analyzing Live RAM in memory dumps. It helps you to search for various artifacts of a user's online activities like chatting, surfing, emailing.

* FAT and NTFS supported
* A number of IMs and browsers supported
* Unique feature of carving NTFS fragmented or compressed drive is implemented
* Export to text, html and xml formats

Retrieve deleted history fragments

You have a seized hard drive or a hard drive image. You would like to extract some information from it, like chats, emails or browser history. However, all the information has been deleted and your file recovery tools do not help you.

In this case, Belkasoft Forensic Carver can help you retrieve information which is still on drive. Even if the information has been deleted, some fragments are still there, and it is possible to recover them when file recovery tools are helpless.

Live memory investigation

The worst case is when a user has chosen not to store any history, which is possible in the most Instant Messengers, and their hard drive does not contain either whole history files or history fragments. What can be done?

The only way to retrieve information in this case is to analyze active computer memory (RAM). If a seized computer was switched on, its memory could contain some parts of conversations or browsing history made by a suspect just before. You can create a memory dump using the windd tool or FTK Imager and then analyze this dump using Belkasoft Forensic Carver.
Requirements: Microsoft.NET Framework 3.5

   



Top Software

New Software

Top Search

Latest Reviews