Using this specialized software forensic investigators can manage and examine digital evidence. It is possible to mount hard drives as read only virtual volumes.
P2 eXplorer
P2 eXplorer is a Windows utility for examining data from various types of storage devices without tampering with the source. There is support for compressed and encrypted PFR disk images. You are able to search for specific files and generate official forensic reports.
Data analysis
Like SIFT Workstation, this program lets users mount hard drive images for detailed examination of the content. It is possible to enable write protection to avoid any modification of original files.
You can work with WinImage packages, RAW disk images from Linux and other types of virtual partitions. Moreover, encrypted and compressed files are compatible with this tool as well. It is worth mentioning that P2 eXplorer is discontinued and no longer supported by the developer. The installation files are not available.
Mounting process
After starting the application users are instructed to import disk images. Compatible partitions will automatically appear as separate drives. There is a list of mounted volumes with detailed information about the amount of occupied space, overall capacity and current status.
Tools for calculating MD5 checksums and verifying existing hashes are included. This functionality is helpful for ensuring that important files are not changed in any way.
Features
- free to download and use;
- oriented toward professional forensic investigators;
- provides tools for examining data on any hard drive;
- it is possible to find specific files and generate detailed reports;
- compatible with all modern versions of Windows.