InVitro is pre-release software and is not on sale yet. Prices and licence terms on this site are provisional.

Features

What the current build opens and what it does with it. The editions table shows which edition includes each part.

Formats

Filesystems 17
  • NTFS
  • FAT12, FAT16, FAT32
  • exFAT
  • ext2, ext3, ext4
  • HFS+
  • APFS
  • XFS
  • Btrfs
  • ZFS
  • ReFS 3.x
  • F2FS
  • UFS1, UFS2
  • ReiserFS
  • UBIFS
  • JFFS2
  • ISO 9660 with Joliet and Rock Ridge
  • UDF

Folders are listed straight from the volume, so you can browse before the full tree has been built. Checksums are verified on read for Btrfs, ZFS and ReFS. APFS encrypted volumes mount with their file data marked encrypted. UBIFS and JFFS2 are read from MTD dumps; raw NAND dumps with spare areas are not supported.

Image containers
  • Raw and split raw
  • E01 (EWF)
  • AFF4
  • VHD, VHDX
  • VMDK
  • VDI
  • QCOW2
  • DMG (unencrypted UDIF)
  • .ivi
  • cue/bin, CloneCD, NRG, ISO

A split set with a segment missing still opens; the missing range reads as unavailable. A folder of loose files can be added as logical evidence.

Partitions and volume managers
  • MBR
  • GPT
  • Linux LVM2
  • Windows dynamic disks (LDM)
  • BSD disklabels
  • UBI

Multi-device Btrfs and ZFS pools are assembled by their filesystem modules. RAID assembly is coming as a separate add-on and is not part of any edition yet.

Encryption and snapshots
  • BitLocker
  • LUKS1, LUKS2
  • F2FS per-file encryption
  • Volume Shadow Copies

FileVault and encrypted DMG are not supported yet.

Nesting

Every layer becomes a drive, and detection runs again on it. Tested combinations include a VHDX holding GPT holding NTFS, FAT32 and exFAT; LUKS2 holding ext4; E01 and QCOW2 holding ext4. A disk image found as a file inside a filesystem opens as a drive in place.

Imaging

  • Physical disks, single partitions, USB and flash media, to raw (dd) or .ivi with the per-sector read map and hashes.
  • Multi-pass reading, skip on error, retries, pause and resume. A Failing HDD profile sets these in one click.
  • ATA SMART, NVMe health, HPA and DCO, read through an allowlist of read-only commands.
  • ddrescue mapfiles in and out.
  • Verify an image against its stored hashes.
The Imaging workspace with source, destination format, segment size, hashes, sector range, live map and error timelineThe Imaging workspace with source, destination format, segment size, hashes, sector range, live map and error timeline
The Imaging workspace in Simple mode. Advanced and Expert show the rest of the read strategy.

Optical discs

  • CD, DVD and BD: every session and track, including tracks missing from the table of contents.
  • Raw CD reads keep subchannel data and C2 error pointers, with retry passes.
  • Export to CloneCD, cue/bin, ISO and WAV.

Validated on a simulated drive built from real disc images. See Validation.

Optical acquisition of a CD-R with three sessions and four tracks on a simulated drive, with retry passes and export formatsOptical acquisition of a CD-R with three sessions and four tracks on a simulated drive, with retry passes and export formats
A three-session CD-R on the simulated drive. Track 04 is not in the table of contents and is read anyway.

Browsing and viewers

Case tree

Evidence, partitions, layers and volumes in one tree. Selecting a node gives it a ribbon tab with the commands its module provides, such as Use FAT 2, Compare FAT copies or Scan MFT records.

Hex and structures

Each decoded field of a boot sector, superblock or record has a Go button that jumps to its bytes. A gutter shows the read status of every row.

Drive map

Read status, partition candidates and the regions modules paint, such as $MFT, $LogFile and used or free clusters, at any zoom, with an entropy layer.

Hex and structure view of an NTFS boot sector with a read-status gutter and the decoded boot-sector fields, each with a Go buttonHex and structure view of an NTFS boot sector with a read-status gutter and the decoded boot-sector fields, each with a Go button
An NTFS boot sector. Every field checked against the volume has a tick.
The drive map of a split raw image with a missing segment and partition candidatesThe drive map of a split raw image with a missing segment and partition candidates
A split raw image with its third segment missing.

Recovery

  • Deleted files in place, plus orphans and lost-and-found. On FAT and HFS+, files whose clusters were reused are flagged.
  • Partition recovery that finds volumes from their own metadata and validates each candidate before you adopt it.
  • Carving over a node, a sector range or unallocated space only, with structure checks, fragment gluing for JPEG, MP3, MPEG and ZIP, and a verdict per file. Carving pauses and resumes, also after a restart.
  • For each volume, the metadata copy to read from (FAT1 or FAT2, $MFTMirr, backup superblocks, ZFS uberblocks, APFS checkpoints) is chosen automatically, the reason is recorded in the case, and you can switch it.
  • Compressed streams that fail to decode are reported as failures, never zero-filled.
  • Export with a manifest.
Carving results: per-type counts, a scope map, and nine carved files with verdicts, offsets and verified sizesCarving results: per-type counts, a scope map, and nine carved files with verdicts, offsets and verified sizes
Carving the free space of a FAT32 stick image.

Forensic analysis

Hashing

MD5, SHA-1, SHA-256, ssdeep and TLSH. Hash sets with NSRL and VICS import. One content pass reads each file once and feeds hashing, type detection, the index and YARA together.

Search

Keywords, patterns and regular expressions over raw sectors or file contents, in several encodings, plus an index for repeated searches.

YARA and Sigma

YARA-X rules over files; Sigma rules over Windows event logs. Each match links to its file, its bytes and its place on the timeline.

Windows artifacts

Registry, event logs, LNK, Prefetch, jump lists, the USN journal, SRUM, WebCache, shellbags, Recycle Bin and scheduled tasks, each linked to its source.

Documents and mail

PST, MSG and EML; OLE2 and OOXML Office files with macros flagged; PDF, SQLite, ESE, plists and EXIF. ZIP, 7z, RAR, TAR and CAB expand inline.

Timeline and gallery

A case-wide timeline, a picture gallery with visual-similarity search, and tags, bookmarks and notes from every view.

The Timeline workspace: a histogram of 3,776 events, filters by source and an event list with 100 ns precisionThe Timeline workspace: a histogram of 3,776 events, filters by source and an event list with 100 ns precision
The timeline of one NTFS volume, split by source.

Decryption

  • BitLocker: password, recovery key, .bek file, VMK or FVEK.
  • LUKS1 and LUKS2: passphrase, key file or master key; PBKDF2 and Argon2id.
  • Try a list of known passwords against a volume.
  • Keys are stored in the case, so volumes unlock again when the case is reopened.

InVitro does not brute-force passwords. It exports hashes in Hashcat and John the Ripper formats for BitLocker, LUKS and ZIP, and reads a Hashcat potfile back to unlock.

Reports

  • Templates: full case, evidence summary, checked items and timeline extract. Sections switch on, off and reorder, with a live preview.
  • HTML, PDF and CSV; hash lists; checked items exported with a manifest.
  • Report packages (.ivrep) carry findings between cases. A package made from different evidence is refused, with the reason.
  • A headless command line creates or opens a case, adds evidence, runs a processing profile, writes the report and exits with a status code.
The Reports and Export workspace with the Full case template and its live previewThe Reports and Export workspace with the Full case template and its live preview
Choosing sections for the Full case report.

Modules

Every container, partition scheme, decryption layer, filesystem, file type and content analyser in InVitro is a module on one public contract. A module declares its commands, options, map regions and structure views, and the application builds its ribbon tab, options and Inspector sections from them. Third-party modules load in the Complete edition. Developers.