© Copyright 2020 XtremeForensics

Key Features - Standard Edition (Perpetual Licence)

  • Data capture, analysis, investigation and dissemination

  • An easy-to-use interface

  • Five built-in, fast and thorough search engines

  • Built-in development environment

  • Built-in file viewers for hundreds of file types

  • Salvage engine

  • Extremely fast hash engines and automated data reduction techniques

  • Built-in e-mail store processing, searching and viewing

  • Filesystem, file and e-mail recovery

  • Multiple categorization features

  • Registry viewing and searching

  • Virus/Trojan search and identification

  • VMware virtual disk production from devices or images

  • Context dictionary production for password cracking

  • The ability to create encrypted containers for dissemination

  • Support for all common archive file formats

  • Automatic deconstruction of forensically-useful file types

  • Sorting, grouping and filtering of files and e-mail.

  • Advanced analysis functions

  • Advanced MS Outlook e-mail recovery

  • Password protected file detection

Additional Features - Advanced Edition (Annual Licence)

  • Xtreme File Recovery -  able to recover deleted files AND metadata from Ext 3 & 4 filesystems (in addition to NTFS, ExFAT, HFS etc.) PLUS recovering deleted files and their metadata from Volume Shadow Copies.

  • IXImager Creation - extremely fast and versatile booting and imaging tool .

  • VSS enabled - automatically recreates and processes volume snapshots and adds them to the folder tree

v10-Powerful and Easy to Use

Over the past few years ILOOK has undergone a huge amount of development, particularly in relation to Apple file systems, and as ILOOKix v10 it is now available for use outside of the law enforcement, intelligence and military environments. In addition, to cater for the needs of practitioners working on smaller cases, there is now a 'Standard' version which has the the features included in the 'Advanced' version but does not enable the creation of IXImager boot media or allow the use of XtremeFileRecovery.

ILOOKix is designed for ease of use, intuitive interface, comprehensive processing and stability in the face of ever-growing volumes of data. It is full of features designed to aid the investigator, from the ability to use 'one-click' processing options to the comprehensive property sheets associated with each object.

ILOOKix runs perfectly on a Virtual Machine and each ILOOKix licence permits up to 3 instances on the same host (in both Standard and Advanced versions).

Sample Screenshots

Simple but powerful processing options

Built-in Registry processing and viewing

Comprehensive email processing and viewing

Volume Shadow Copies automatically included in folder view

ILOOKix Firsts

With its long history in the field of digital forensics, ILOOK (and now ILOOKix) has managed to be the first tool to provide some significant features for practitioners. This achievement includes being the first forensic tool to map HFS+, NTFS compressed, Linux Ext 3 & 4  filesystems as well as VDI and VMDK virtual disks. The process of being at the forefront of feature development continues with ILOOKix being the first tool to: 

  • generically deconstruct SQLite databases, Plists and BPlists

  • recover deleted data from volume shadow copies

  • correctly process ALL Windows 10 compressed data types

Operating environments for ILOOKix v10 

Recommended minimum requirements

  • i5 processor or equiv

  • 8 GB RAM

  • Fast rotational disk for case database

  • MS Windows 7 Professional 64bit

Note: ILOOKix will still run on systems below these specifications but performance will be greatly reduced

Typical workstation specification

  • i7 processor or equiv

  • 16 GB RAM

  • 250 GB SSD disk for case databases

  • MS Windows 10 Professional 64bit

Typical VM host specification

  • i7 processor

  • 16 GB RAM per VM

  • SSD disk for case databases

  • MS Server 2012

Typical VM guest specification

  • All cores allocated

  • 16 GB RAM - dedicated not dynamic

  • 250 GB Virtual Disk located on an SSD for case databases

  • MS Windows 10 Professional 64bit