Developers
The built-in filesystems, containers and decoders are modules on the same public contract a third-party module uses. A module supplies the format logic; the case tree, ribbon, options, drive map and Inspector come from the application.
Module kinds
| Kind | Reads | Produces |
|---|---|---|
| Container | An image file or segment set | One drive |
| Partitioning / volume manager | A disk | One drive per partition or volume |
| Layer | An encrypted or transformed volume | One drive with the decoded content |
| Filesystem | A volume | A file tree; every file opens as a drive |
| Volume version | A filesystem's snapshots | Earlier versions to browse |
| File type and analyser | A file | Previews, metadata, timeline events, artifacts |
| Content analyser | Each file's content, streamed once by the content pass | Attributes, findings and digests |
How a module fits in
A module never opens a path or a device. It reads a drive through an extent map, so a filesystem module mounts the same way inside an E01, a partition, a decrypted volume or a file in another filesystem.
It declares commands (with icons and enablement rules), typed options, map legends and structure views. The application turns those into a ribbon tab, an options grid, drive-map layers and Inspector sections.
Reads return sector statuses alongside the bytes, and a failed decode is an error rather than zeros. The test kit's conformance tests and corruption injector check both for your module.
In outline
[assembly: InVitroModule(typeof(MyContentModule))]
public sealed class MyContentModule : IContentAnalyzerModule
{
// Declare what to receive (sizes, types, header
// only or the whole stream). The content pass hands
// over each file as ordered chunks, with unreadable
// gaps and their statuses; push attributes, digests
// and findings to the sink.
}
- Modules reference the public Core contract only and are found by the capabilities they implement.
- The contract is versioned; the loader checks compatibility.
- Third-party modules load in the Complete edition.
SDK questions and format partnerships: support@invitroforensics.com.