ADF Digital Evidence Investigator® (DEI) is the industry leading digital investigation tool for collecting files and artifacts - with evidence presented in a timeline view. Now you can conduct intelligent digital investigations easier, faster and smarter to reduce forensic backlogs.
Easily adapting to rapidly evolving digital forensic needs and circumstances, DEI is all about speed, scalability, ease-of-use, and relevant results. DEI is a fully automated and highly configurable artifact and file collection tool. Relevant social media, peer to peer file sharing, web browsing, and email data can be quickly recovered along with many other file types. You can also minimize and eliminate the need for complex configurations, manually parsing files, or running multiple scripts.
Customer Benefits and Key Features
Highly configurable artifact and file collection including social media, P2P, bitcoin, cloud storage, user login events, anti-forensic tools, saved credentials and files shared via Skype
Forensically Sound
Able to investigate live powered on computers, dead powered off computers, forensic images, the contents of folders and network shares (including shares made available by NAS devices)
Rapidly search suspect media using large hash sets (>30 million), including Project VIC and CAID
Automatic tagging of hash and keyword matches
Automatic linking of files with artifacts
Automatic time zone detection
Powerful keyword and regular expression search capability to find relevant files and artifacts
Search and collect emails including Windows Mail 10
Ability to define new file types and select individual ones to be processed
Display provenance, including comprehensive metadata, of all relevant files and artifacts
Comprehensive video preview and frame extraction
Recover images from unallocated drive space
A unique timeline that combines files and artifact records, with a user's actions into a single view
Process NTFS, FAT, HFS+, EXT, ExFAT and YAFFS2 file systems
Powerful reporting capabilities (HTML and CSV)
Portable standalone viewer to easily share results with others (i.e., prosecutors or other investigators)
Out-of-the-box imaging capabilities
64-bit architecture delivers high performance and scalability
Powerful booting capability (including UEFI secure boot and Macs) provides access to internal storage that cannot easily be removed from computers
Ram Capture capability
Detect and warn of BitLocker and FileVault2 protected drives
Decrypt and scan or image BitLocker volumes including those using the new AES-XTS encryption algorithm introduced in Windows 10
Collect protected and corrupted files for later review
The Digital Evidence Investigator® (DEI) Software Comes With: