Documentation

Manual and API reference

The user manual ships with every installation: press F1 or open Help. Both the manual and the API reference are published on this site at release.

User manual

For examiners and recovery technicians.

  • Getting started: cases, adding evidence, the screen layout
  • Acquisition: disks, partitions, flash and optical media; retries and resume; raw and .ivi images and read maps
  • The case tree, module commands and options
  • Browsing, preview, hex and structure views, the drive map and the status colours
  • Recovery: deleted files, lost and found, partition recovery, carving, optical data outside the file tree
  • Decryption and keys; Hashcat and John the Ripper export
  • Hashing, the content pass, YARA and Sigma, search, artifacts and the timeline
  • Reports, the command line, troubleshooting and a glossary

Published at release

API reference

For module authors and automation.

  • The module contract and how versions stay compatible
  • Drives, node maps and sector statuses
  • Probes and confidence, result sinks, commands, options, map legends and structure views
  • Guides for each module kind: containers, partitioning, layers, filesystems, file types, analysers, content analysers and volume versions
  • The test kit and conformance bases; packaging and installing a module
  • Reference pages generated from the public API

Published at release  Developers overview →

Command line

InVitro runs a processing profile on a case without the main window: it creates or opens the case, adds evidence, runs the profile, writes the completion report, and exits with a code that says how it went.

InVitro.exe --case new:D:\cases\Example --add E:\evidence\disk.E01 --profile Triage --report evidence-summary --out D:\out --exit

Available in the Forensic and Complete editions. The full switch list is in the manual.