InVitro is pre-release software and is not on sale yet. Prices and licence terms on this site are provisional.

Documentation

The user manual ships with the program: press F1, or open Help. The manual and the API reference will also be published here at release.

User manual

  • Cases, adding evidence and the screen layout
  • Imaging disks, partitions, flash and optical media; retries and resume; raw and .ivi images and read maps
  • The case tree, module commands and options
  • Browsing, preview, hex and structure views, the drive map and the status colours
  • Deleted files, lost and found, partition recovery and carving
  • Decryption, stored keys, and Hashcat and John the Ripper export
  • Hashing, the content pass, YARA and Sigma, search, artifacts and the timeline
  • Reports, the command line, troubleshooting and a glossary

API reference

  • The module contract and how versions stay compatible
  • Drives, extent maps and sector statuses
  • Probes, result sinks, commands, options, map legends and structure views
  • A guide and a sample for each module kind
  • The test kit, conformance tests, and packaging a module
  • Reference pages generated from the public API

Writing a module

Command line

InVitro can run a processing profile without opening its window: it creates or opens the case, adds evidence, runs the profile, writes the report and exits with a code that says how it went.

InVitro.exe --case new:D:\cases\Example --add E:\evidence\disk.E01 --profile Triage --report evidence-summary --out D:\out --exit

Forensic and Complete editions. The manual lists every switch.