POWERFUL AND EASY TO USE
INNOVATION IN PRACTICE — DIGITAL FORENSICS
V10
POWERFUL AND EASY TO USE
Since its first use with the UK security services back in the late 1990s and later with global law enforcement ILOOK has undergone a huge amount of development, particularly in relation to Apple file systems. As ILOOKix v10 it is now available for use outside of the law enforcement, intelligence and military environments. In addition, to cater for the needs of practitioners working on smaller, less demanding cases, there is now a 'Standard' version which does not include the ground-breaking XtremeFileRecovery capability, automatic deconstruction of volume shadow copies (added to the folder tree) and IXImager, the world’s fastest imaging and data recovery tool.
STANDARD EDITION (PERPETUAL LICENCE)
KEY FEATURES
-
Data capture, analysis, investigation and dissemination
-
An easy-to-use interface
-
Five built-in, fast and thorough search engines
-
Built-in development environment
-
Built-in file viewers for hundreds of file types
-
Salvage engine
-
Extremely fast hash engines and automated data reduction techniques
-
Built-in e-mail store processing, searching and viewing
-
Filesystem, file and e-mail recovery
-
Multiple categorization features
-
Registry viewing and searching
-
Virus/Trojan search and identification
-
VMware virtual disk production from devices or images
-
Context dictionary production for password cracking
-
The ability to create encrypted containers for dissemination
-
Support for all common archive file formats
-
Automatic deconstruction of forensically-useful file types
-
Sorting, grouping and filtering of files and e-mail.
-
Advanced analysis functions
-
Advanced MS Outlook e-mail recovery
-
Password protected file detection
ADVANCED EDITION (ANNUAL LICENCE)
ADDITIONAL FEATURES
-
VSS enabled
-
Automatically recreates and processes volume snapshots and adds them to the folder tree
-
-
Xtreme File Recovery:
-
Able to recover deleted files AND metadata from Ext 3 & 4 filesystems (in addition to NTFS, ExFAT, HFS etc.)
-
Recovering deleted files and their metadata from Volume Shadow Copies.
-
-
IXImager Creation
-
Extremely fast and versatile booting and imaging tool .
-
ILOOKix FIRSTS
With its long history in the field of digital forensics, ILOOK (and now ILOOKix) has managed to be the first tool to provide some significant features for practitioners. This achievement includes being the first forensic tool to map HFS+, NTFS compressed, Linux Ext 3 & 4 filesystems as well as VDI and VMDK virtual disks. The process of being at the forefront of feature development continues with ILOOKix being the first tool to:
-
generically deconstruct SQLite databases, Plists and BPlists
-
recover deleted data from volume shadow copies
-
correctly process ALL Windows 10 compressed data types
SAMPLE SCREENSHOTS
SIMPLE BUT POWERFUL PROCESSING OPTIONS
BUILT-IN REGISTRY PROCESSING & VIEWING
COMPREHENSIVE EMAIL PROCESSING & VIEWING
VOLUME SHADOW COPIES AUTOMATICALLY INCLUDED IN FOLDER VIEW
OPERATING ENVIRONMENTS FOR ILOOKix V10
RECOMMENDED MINIMUM REQUIREMENTS
-
i5 processor or equiv
-
8 GB RAM
-
Fast rotational disk for case database
-
MS Windows 7 Professional 64bit
​
​
Note: ILOOKix will still run on systems below these specifications but performance will be greatly reduced
TYPICAL WORKSTATION SPECIFICATION
-
i7 processor or equiv
-
16 GB RAM
-
250 GB SSD disk for case databases
-
MS Windows 10 Professional 64bit
TYPICAL VM HOST SPECIFICATION
-
i7 processor
-
16 GB RAM per VM
-
SSD disk for case databases
-
MS Server 2012
TYPICAL VM GUEST SPECIFICATION
-
All cores allocated
-
16 GB RAM - dedicated not dynamic
-
250 GB Virtual Disk located on an SSD for case databases
-
MS Windows 10 Professional 64bit