Forensic Explorer logo

Forensic Explorer

by GetData Forensics · Since 2013
No reviews yet
Active1+ countriesCloud
Quick facts
VendorGetData Forensics
Year launched2013
StatusActive
LocationSuite 204, 13A Montgomery St Kogarah NSW 2217, Australia
Countries served1+
Languages8
Integrations
Free tier
Free trial
Contact salesYES

About Forensic Explorer

Forensic Explorer is a forensic analysis software from GetData Forensics that focuses on analyzing computer evidence. It provides capabilities for recovering, analyzing, and reporting data from physical disks or forensic image files, aiding investigators in data acquisition. This tool includes features like an Evidence Module, a command-line interface (FEX CLI), and comprehensive reporting options, allowing users to conduct thorough investigations. Forensic Explorer supports various file formats and allows the extraction of deleted data to assist in forensic examinations. Key capabilities: Evidence Module FEX CLI Data recovery Comprehensive reporting Multi-format support Best for: forensic analysts and investigators that need to analyze and report on digital evidence effectively.

Forensic Explorer by GetData Forensics is a powerful digital forensics tool designed to assist investigators in conducting thorough and efficient analysis of digital evidence. Primarily targeted at law enforcement, cybersecurity analysts, private investigators, and other professionals in the digital forensics field, the software offers a comprehensive suite of features that supports a full range of forensic tasks. It enables users to acquire, process, analyze, and report on digital evidence from a variety of storage media, including hard drives, USB devices, disk images, and file systems. Its standout features include keyword searching, hash analysis, artifact detection, file carving, registry analysis, email examination, and timeline reconstruction. The user interface of Forensic Explorer is structured for investigative clarity and operational depth. Though designed for professional use, the interface is relatively intuitive, allowing users to navigate through complex evidence sets with ease. The software presents data in multiple structured panes, such as directory trees, file viewers, and metadata displays, providing a layered view of forensic evidence.

Pros & Cons

What users like
  • +Comprehensive: Full suite for forensic analysis from acquisition to reporting.
  • +Deep Access: Accesses all data layers, including hidden and deleted files, across various file systems.
  • +Automated & AI-Powered: Features like automated graphics analysis (CSAM), scripting, and integrated anti-virus streamline tasks.
  • +Flexible Deployment: Supports live boot virtualization, remote analysis, and includes portable tools.
  • +User-Friendly: Customizable GUI suitable for both new and experienced investigators.
What users flag
  • Learning Curve: While user-friendly, the breadth of advanced features might still require significant training for new users.
  • Resource Intensive: Processing large datasets with advanced analysis features can demand significant system resources.
  • Windows-Centric: Primarily runs on Windows, though it can analyze other OS images.
  • No Cloud Native: Not a cloud-native solution for distributed or massive-scale cloud investigations.

Features

Key features

Comprehensive Data Access & Analysis
Provides deep access to all areas of physical or imaged media (file, text, hex level), including system files, slack space, unallocated clusters, and supports various file systems (FAT, NTFS, HFS/+, EXT 2/3/4), ensuring no data is missed.
Powerful Search & Indexing
Offers robust keyword searching at cluster, sector, or byte level using text, regex, or hex expressions, alongside a built-in DTSearch index capability for fast and efficient searches across large datasets, including email content.
Automated Graphics Analysis (CSAM Detection)
Incorporates advanced image recognition and automated analysis specifically for graphics, delivering high detection accuracy with near-zero false positives, including a specialized CSAM detection add-on for law enforcement.
Live Boot Virtualization
Enables investigators to virtualize Windows and Mac forensic images or physical disks directly using VirtualBox or VMWare, allowing for live analysis of the suspect's operating environment and applications.
Integrated Suite of Tools
Includes standalone licenses for FEX-Triage (on-scene collection), FEX-CLI (command-line processing), and Mount Image Pro (MIP), providing a versatile toolkit for various forensic needs.
Flexible & Customizable GUI
Features a highly customizable drag-and-drop GUI that supports multiple monitors and allows users to save and load personalized workspaces to suit their investigative needs.
Powerful Scripting Capabilities
Offers an inbuilt Delphi scripting language with pre-built scripts for common tasks like metadata extraction, registry analysis, and timeline creation, enabling automation of complex investigation tasks.
No Major Version Upgrade Costs
Provides access to the latest software builds without major version upgrade costs for users with valid maintenance, ensuring continuous access to new features and improvements.

Additional features

Comprehensive Data Access
Accesses all areas of physical or imaged media (file, text, hex level), including system files, slack space, unallocated clusters, and supports various file systems (Windows, Mac, Linux) and image formats.
Powerful Search & Indexing
Offers robust keyword searching (text, regex, hex) across entire media and email content, alongside a built-in dtSearch index capability for fast and efficient searches.
Automated Graphics Analysis (CSAM Detection)
Includes advanced image recognition and automated analysis specifically for graphics, delivering high detection accuracy with near-zero false positives, with a specialized CSAM detection add-on for law enforcement.
Live Boot Virtualization
Enables investigators to virtualize Windows and Mac forensic images or physical disks directly using VirtualBox or VMWare for live analysis of the suspect's operating environment.
Integrated Suite of Tools
Comes with standalone licenses for FEX-Triage (on-scene collection), FEX-CLI (command-line processing for automation), and Mount Image Pro (MIP) (mounting forensic images as Windows drives).
Flexible & Customizable GUI
Features a highly customizable drag-and-drop graphical user interface that supports multiple monitors and allows users to save personalized workspaces.
Powerful Scripting Capabilities
Offers an inbuilt Delphi scripting language with pre-built scripts for common tasks like metadata extraction, registry analysis, and timeline creation, enabling automation of complex investigative tasks.
Registry Analysis
Provides tools to open, examine, filter, categorize, and keyword search Windows registry hives, with options for automated analysis.
Email Support
Supports full analysis of various email formats including PST, OST, EDB, and MBOX, with integrated keyword and index search capabilities for email content.
Data Carving & Recovery
Includes an inbuilt data carving tool to recover over 300 known file types and allows for the recovery of deleted folders and partitions.
Anti-Virus & Malware Detection
Features a built-in Cisco Clam anti-virus for identifying known malicious files and supports Yara rules for identifying malware and malicious software based on customizable patterns.
Metadata Extraction & Signature Analysis
Extracts and reports file metadata (EXIF, GPS, MS Office) and automatically verifies file signatures, identifying mismatches with file extensions to detect spoofed files.
RAID Support
Allows working with physical or forensically imaged RAID media, including software and hardware RAID configurations (JBOD, RAID 0, RAID 5, RAID 6).
Shadow Copy Analysis
Easily adds and analyzes Windows shadow copy (Volume Shadow Copy Service) files to recover previous versions of data.
Hash Analysis
Supports applying hash sets (MD5, SHA1, SHA256, CRC, PhotoDNA, ProjectVic) to identify or exclude known files, and offers fuzzy and differential hashing for similarity analysis.
Network Servlet
Connects to and examines remote drives using a deployable network servlet for remote investigations.
Comprehensive Reporting
Features a custom report builder with pre-defined templates for producing detailed investigation reports.
Free Utility Tools
Offers additional free standalone tools like FEX Imager (for forensic imaging), FEX Memory Imager (for memory acquisition), and FEX Viewer (for third-party review of case files).
No Major Version Upgrade Costs
Provides access to the latest software builds without major version upgrade costs for users with valid maintenance.
Multilingual Support
Unicode compliant for searching and viewing data in native languages, and the GUI can be set to multiple languages.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

1
Countries served
8
Interface languages
7
Billing currencies

Available in

All Countries.

Interface languages

EnglishSpanishFrenchGermanItalianPortugueseRussianChinese

Billing currencies

🇦🇺AUD🇨🇦CAD🇨🇳CNY🇪🇺EUR🇬🇧GBP🇯🇵JPY🇺🇸USD

No reviews yet

Be the first to drop a review

Alternatives to Forensic Explorer

EnCase Forensic logo

EnCase Forensic

EnCase Forensic is a digital forensic software from Opentext that enables investigators to gather digital…

FARO Zone 3D (FARO.com) logo

FARO Zone 3D (FARO.com)

FARO Zone 3D is a forensic visualization software from FARO that supports the analysis, reconstruction,…

Autopsy logo

Autopsy

Autopsy is a digital forensics software from Sleuth Kit Labs that provides a comprehensive open-source…

S

SceneWorks

SceneWorks is a software platform from SpheronVR that focuses on creating immersive virtual reality experiences.…

P

Phonexia Orbis Investigator

Phonexia Orbis Investigator is a forensic audio analysis software from Phonexia that provides tools for…

C

CyFIR Investigator

CyFIR Investigator is a digital forensics software from CyFIR that assists in the investigation of…

Often compared with Forensic Explorer

Compare any two tools →
EnCase Forensic logo
EnCase Forensic
Digital Forensics
0.0
FARO Zone 3D (FARO.com) logo
FARO Zone 3D (FARO.com)
Digital Forensics
0.0
Autopsy logo
Autopsy
Digital Forensics
0.0
S
SceneWorks
Digital Forensics
0.0