X-Ways Forensics
Qu'est-ce que X-Ways Forensics ?
X-Ways ForensicsA commercial Windows-based digital forensics suite by X-Ways AG, known for its speed, low system footprint, hex-level visibility, and broad filesystem support — a long-running mainstay of European law-enforcement and corporate DFIR labs.
X-Ways Forensics is a commercial Windows-only forensic platform developed by X-Ways AG (Germany) and widely used in law enforcement, government, and corporate IR labs in Europe and beyond. It descends from the hex editor WinHex and retains an unusually deep, low-level view of evidence: byte-level inspection, raw cluster mapping, manual interpretation of partition tables, custom file-system parsing, and full access to slack space, unallocated space, and damaged structures. Higher-level features include disk imaging, hash-set matching (NSRL and custom), file-type signature identification independent of extension, indexing for full-text search, registry parsing, gallery views, timeline building, $LogFile and $UsnJrnl parsing, full Volume Shadow Copy access, and report generation. Compared to EnCase or FTK, X-Ways is known for being lightweight (single executable, modest RAM/CPU needs), fast on large evidence, and offering very detailed manual control — at the cost of a more terse UI and a steeper learning curve. It supports a wide range of filesystems including NTFS, exFAT, FAT, ReFS, Ext2-4, HFS+, APFS, XFS, UFS, JFS, and several mobile formats via imports.
● Exemples
- 01
An examiner uses X-Ways to manually mount a partially corrupted NTFS volume and recover MFT entries that EnCase had failed to parse.
- 02
A timeline-building task combines $UsnJrnl, $LogFile, and Volume Shadow Copies in a single X-Ways case to reconstruct file-system changes across a multi-day incident.
● Questions fréquentes
Qu'est-ce que X-Ways Forensics ?
A commercial Windows-based digital forensics suite by X-Ways AG, known for its speed, low system footprint, hex-level visibility, and broad filesystem support — a long-running mainstay of European law-enforcement and corporate DFIR labs. Cette notion relève de la catégorie Forensique et réponse en cybersécurité.
Que signifie X-Ways Forensics ?
A commercial Windows-based digital forensics suite by X-Ways AG, known for its speed, low system footprint, hex-level visibility, and broad filesystem support — a long-running mainstay of European law-enforcement and corporate DFIR labs.
Comment fonctionne X-Ways Forensics ?
X-Ways Forensics is a commercial Windows-only forensic platform developed by X-Ways AG (Germany) and widely used in law enforcement, government, and corporate IR labs in Europe and beyond. It descends from the hex editor WinHex and retains an unusually deep, low-level view of evidence: byte-level inspection, raw cluster mapping, manual interpretation of partition tables, custom file-system parsing, and full access to slack space, unallocated space, and damaged structures. Higher-level features include disk imaging, hash-set matching (NSRL and custom), file-type signature identification independent of extension, indexing for full-text search, registry parsing, gallery views, timeline building, $LogFile and $UsnJrnl parsing, full Volume Shadow Copy access, and report generation. Compared to EnCase or FTK, X-Ways is known for being lightweight (single executable, modest RAM/CPU needs), fast on large evidence, and offering very detailed manual control — at the cost of a more terse UI and a steeper learning curve. It supports a wide range of filesystems including NTFS, exFAT, FAT, ReFS, Ext2-4, HFS+, APFS, XFS, UFS, JFS, and several mobile formats via imports.
Comment se défendre contre X-Ways Forensics ?
Les défenses contre X-Ways Forensics combinent habituellement des contrôles techniques et des pratiques opérationnelles, comme détaillé dans la définition ci-dessus.
Quels sont les autres noms de X-Ways Forensics ?
Noms alternatifs courants : X-Ways, X-Ways Forensics suite.
● Termes liés
- forensics-ir№ 361
Forensique disque
Analyse des supports de stockage non volatils — HDD, SSD, clés USB — pour récupérer et interpréter les artefacts du système de fichiers, des applications et de l'OS.
- forensics-ir№ 471
Imagerie forensique
Copie bit à bit d'un support de stockage, vérifiée par empreintes cryptographiques, exploitable pour l'analyse et recevable en justice.
- forensics-ir№ 460
Carving de fichiers
Technique forensique qui récupère des fichiers depuis l'espace non alloué ou des données brutes en reconnaissant signatures, en-têtes et pieds de fichier, sans recourir aux métadonnées du système de fichiers.
- forensics-ir№ 751
MFT (Master File Table)
Structure de metadonnees centrale de NTFS qui stocke un enregistrement de 1024 octets par fichier ou repertoire du volume et constitue la base de l'analyse forensique du systeme de fichiers Windows.
- forensics-ir№ 001
$UsnJrnl ($J)
Journal des numeros de sequence de mise a jour de NTFS qui enregistre chaque operation du systeme de fichiers et fournit aux forensiques une frise chronologique a haute resolution.
- forensics-ir№ 420
EnCase
EnCase est une gamme de produits commerciaux d'investigation numerique d'OpenText (a l'origine Guidance Software), largement utilisee par les forces de l'ordre et les enqueteurs en entreprise depuis la fin des annees 1990.