...
Forensic Image File Formats
HstEx® Blade® natively supports a number of different image and output file formats. The following table represents a summary of the supported file types.
| File Format | File Extensions | ||||||
|---|---|---|---|---|---|---|---|
| EnCase® Image File (EVF / Expert Witness Format) | *.e01 | ||||||
| EnCase® Evidence File Format v2 | *.ex01 | ||||||
| EnCase® Logical Evidence File Format v1 | *.L01 | ||||||
| EnCase® Logical Evidence File Format v2 | *.Lx01 | ||||||
| SMART/Expert Witness Image File | *.s01 | ||||||
| X-Ways Forensics Image File | *.e01 | ||||||
| VMWare Virtual Disk File | *.vmdk | ||||||
Multi-Volume ZIP Archive
| *.zip | ||||||
| AFF v3 | |||||||
| Virtual Hard Disk | *.vhd | ||||||
| Segmented Image Unix / Linux DD / Raw Image Files | *.000, *.0000, *.00000, *.001, *.0001, *.00001 | ||||||
| Single Image Unix / Linux DD / Raw / Monolithic Image Files | *.dd; *.img; *.ima; *.raw | ||||||
| Memory Dumps | *.dmp; *.dump; *.crash; *.mem; *.vmem; *.mdmp | ||||||
| Binary Dumps | *.bin; *.dat; *.unallocated; *.rec; *.data; *.binary | ||||||
| Mobile Phone Raw Binary Memory Dumps | *.bin |
Direct Sector Access to Physical and Logical Devices
...