Internet Evidence Finder Standard Edition 4.2
Internet Evidence Finder Standard Edition 4.2 Ranking & Summary
Internet Evidence Finder Standard Edition 4.2 description
Internet Evidence Finder Standard Edition 4.2 comes to users as an impressive and useful application which can search a hard drive or files for Internet related artifacts. It is a data recovery tool that is geared towards digital forensics examiners but is designed to be straightforward and simple to use.
IEF v4 searches the selected drive, folder (and sub-folders, optionally), or file (memory dumps, pagefile.sys, hiberfil.sys, etc) for Internet artifacts. A case folder is created containing the recovered artifacts and the results are viewed through the IEF v4 Report Viewer where reports can be created and data exported to various formats.
IEF has gone through a great deal of revisions and transformations in its journey to Version 4. There is also now a Portable Edition of IEF v4.
Major Features:
- New, simplified Graphical User Interface
- 11 new searches for grand total of 30 artifacts IEF can search for (see below)
- The file system is now also searched instead of just a sector level search
- Can search Unallocated Clusters only, optionally including file slack space
- On NTFS drives, the MFT (Master File Table) is searched for resident deleted files
- All recovered data outputs to a report case folder now and viewed with the IEF Report Viewer, full report can be created or data exported to multiple formats
- Yahoo!® Messenger existing log files are now parsed without requiring usernames
- Yahoo!® Messenger chat log validation has been improved, with support for date ranges and message text filtering
- The compressed data in Hiberfil.sys files is decompressed on-the-fly during searches making it easy to recover artifacts within these files
- 5 total search functions (Quick, Full, Unallocated Only, Full – Sector level, and Files/Folders)
- Major re-write of most old searches and program code to improve speed and stability
- Facebook® live chat search completely rewritten to find even more chat, including damaged fragments
- Facebook® unicode text is now converted
- Updated MSN®/Windows Live Messenger® search re-written to find more chat, faster
- New Portable Edition that can run on live systems
- Portable and Standard versions can both access locked files such as the Pagefile.sys file on a live system
- Volume Shadow Copies can be mounted and searched (Quick Search or Full – Sector Level Search) in the Portable Edition
- Firefox v5 support added
-
- All IEF searches that relate to Firefox can now recover deleted records/records from memory dumps/live records/etc that are from Firefox v5 SQLite databases (with v3/v4 still supported as well).
- Internet Explorer v9 support added
- IEF can now also recover IE v9 Recovery/InPrivate URLs, while still supporting IE v8 URLs as well.
- Added raw searching of the $MFT on NTFS drives
-
- The entire raw $MFT is now searched in the Quick/Full searches (option to skip searching the $MFT also added).
- Updated Gigatribe search, updated Unicode support in Facebook searches
- Quick/Full Search now checks for the existence of a “Windows.old” folder structure
-
- If a user upgrades Windows® without formatting the partition first, files that were used in the previous version of Windows® are stored in the Windows.old folder. This folder structure can hold a great deal of user data.
- Report Viewer updated to create HTML reports that are more Linux-friendly
- Minor updates to the interface (no small window at end of search, everything kept on main window), added verbose/basic logging option
- Minor bugs fixed, including issue with some systems crashing when IEF accessed certain locked files
Requirements:
- System requirements are minimal; if you have the required hardware for the operating system you are running, you can run IEF. However, a fast CPU and at least 2GB of RAM is recommended.
- The speed of the storage device being searched (or containing the files being searched) will make a large difference in speed as well. A RAID 0 or SSD set-up is recommended.
Internet Evidence Finder Standard Edition 4.2 Screenshot
Internet Evidence Finder Standard Edition 4.2 Keywords
Bookmark Internet Evidence Finder Standard Edition 4.2
Internet Evidence Finder Standard Edition 4.2 Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
