Welcome to my blog!
AccessData.com provides a suite of forensics tools.
Evidence Item: Select the evidence item to see the loaded content.
Items are broken up by actual file type. word docs, plain text docs, html docs, etc and anything plaintext will be able to be read there. Archives are zipped files. Slack free space (so if it found files in the slack space).
Allows us to look at the files like we would through windows explorer. From here we can pick off low-hanging fruit in forensics investigation (my pictures / my documents) folders.
The graphics tab is meant for finding easy stuff and analyzing image files.
Additional ResourcesBuild a word index after an image has been processed