WinHex is a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards. X-Ways Forensics is an an advanced computer examination and data recovery software. It is based on the WinHex hex and disk editor and part of an efficient workflow model where computer forensic examiners share data and collaborate with investigators that use X-Ways Investigator. X-Ways Investigator is based on X-Ways Forensics and is a subset thereof. It’s simplified user interface offers much fewer technical options than WinHex and X-Ways Forensics, so that investigators can better concentrate on the matter at hand.
X-Ways Forensics, the forensic edition of WinHex, is a powerful and affordable integrated computer forensics environment with numerous forensic features, rendering it a powerful disk analysis tool: capturing free space, slack space, inter-partition space, and text, creating a fully detailed drive contents table with all existing and deleted files and directories and even alternate data streams (NTFS), Bates-numbering files, and more. Picture gallery, file preview, calendar/timeline display. Also serves as a low-level disk imaging and cloning tool that creates true mirrors (including all slack space) and reads most drive formats and media types, and supports drives and files of virtually unlimited size (even terabytes on NTFS volumes!).
X-Ways Forensics and WinHex can natively interpret and show the directory structure on FAT, NTFS, Ext2/3, Reiser, CDFS, and UDF media and image files. It performs safe recoveries on hard disks, memory card, flash disks, floppy disks, ZIP, JAZ, CDs, DVDs, and more. It incorporates several automated file recovery mechanisms and allows to conveniently recover data manually. WinHex provides sophisticated, flexible and lightning-fast simultaneous search functions that you may use to scan entire media (or image files), including slack, for deleted files, hidden data and more. Via physical access, this can be accomplished even if a volume is undetectable by the operating system e.g. due to an unknown or a corrupt file system.
X-Ways Investigator is a powerful investigation/document analysis/report generation application for law enforcement, intelligence agencies, and the private sector. It runs under Windows. It was designed for investigators who are specialized in areas such as accounting, building laws, money laundering, corruption, homicide, child pornography, etc., also for investigative analysts, agents, attorneys, p
• Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash,
• Powerful directory browser for FAT, NTFS, Ext2/3, ReiserFS, CDFS, UDF
• RAM editor, providing access to other processes’ virtual memory
• Data interpreter, knowing 20 data types
• Editing data structures using templates (e.g. to repair partition table/boot sector)
• Concatenating and splitting files, unifying and dividing odd and even bytes/words
• Analyzing and comparing files
• Particularly flexible search and replace functions
• Disk cloning, with a specialist license also under DOS
• Drive images & backups (optionally compressed or split into 650 MB archives)
• Programming interface (API) and scripting (professional & specialist licenses only)
• 128-bit encryption, checksums, CRC32, hashes (MD5, SHA-1, …)
• Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
• Import all clipboard formats, incl. ASCII hex values
• Convert between binary, hex ASCII, Intel Hex, and Motorola S
• Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
• Instant window switching. Printing. Random-number generator.
• Supports files more than 4 GB. Very fast. Easy to use.
* not available
OS: Windows 2K / XP / XP 64 bit / Vista / Vista 64 bit / 7 / 7 64 bit / 8 / 8 64 bit / 2003 / 2008 / 2008 64 bit / 2008 R2