Overview of HstEx®

HstEx® v5 is an advanced, Windows-based, multi-threaded, forensic data recovery solution which has been designed to recover deleted browser history and cache data from a variety of source forensic evidence files as well as physical and logical devices. Specifically designed to work in conjunction with NetAnalysis® (and is provided as part of the suite), this powerful software can recover deleted data from a variety of Internet browsers, whether they have been installed on Windows, Linux or Apple Mac systems. In contrast with NetAnalysis® which works at the logical file system level (reading live files), HstEx® works at a much lower level, recovering data by searching for artefacts at sector level.

HstEx® supports a number of different source evidence types such as EnCase® e01 (Expert Witness) image files, EnCase® 7 ex01 files, AccessData® FTK™ image files or traditional monolithic and segmented dd image files. It also supports direct sector access to physical and logical devices such as hard disks. HstEx® natively supports these sources for direct access and does not rely upon third party mounting software.

HstEx® is able to extract browser records directly from source forensic files enabling the recovery of evidence, not only from unallocated clusters, but also from cluster slack, memory dumps, paging files and system restore points amongst others. It is an extremely powerful tool in your forensic tool-box.

From a forensic perspective, it is important that HstEx® is used in combination with NetAnalysis®.



Recently Updated Pages

Navigate Documentation

Search Documentation