Skip to end of metadata
Go to start of metadata

Supported Image File Formats

HstEx v3 supports a number of forensic image and output file formats.  The following table presents a summary of the supported file types.

  

Supported Forensic Image Formats
EnCase®  v1-7 Image File (EVF / Expert Witness Format)
*.e01
AccessData®  FTK Image Files
*.e01, *.001, *.s01
Advanced Forensic Format (AFF®)*.aff;*.afd,*.afm
SMART/Expert Witness Image File
*.s01
X-Ways Forensics Image File
*.e01
VMWare Virtual Disk File
*.vmdk
Virtual Hard Disk File
*.vhd
Segmented Image Unix / Linux DD / Raw Image Files
*.000, *.001
Single Image  Unix / Linux DD/Raw Image Files
*.dd; *.img; *.ima; *.raw
Memory Dumps
*.dmp; *.dump; *.crash; *.mem; *.vmem; *.mdmp
Binary Dumps
*.bin; *.dat; *.unallocated; *.rec; *.data; *.binary
Micro Systemation Extraction File
*.xry

Table 1

Sector Level Access to Physical / Logical Devices

 HstEx can search any binary file for supported data types and also supports direct sector level access to Physical and Logical devices.  This allows the user to employ hardware / software write blockers and to recover data directly from a disk or external media.