Developers

Build a module, get the whole UI

Everything in InVitro that reads evidence is a module: the built-in filesystems use the same public contract you do. Write the format logic. The case tree, ribbon, options, drive map and Inspector come with it.

Module kindRecognisesProduces
ContainerAn image file or segment setOne drive
Partitioning / volume managerA diskOne drive per partition or volume
LayerAn encrypted or transformed volumeOne drive with the decoded content
FilesystemA volumeA file tree; every file opens as a drive
Volume versionA filesystem's snapshotsBrowsable earlier versions
File type and analyserA filePreviews, metadata, timeline events, artifacts
Content analyserEach file's content, streamed once by the content passAttributes, findings and digests

Everything is a drive

A module never opens a path or a device. It reads a drive through an extent map, so whatever you write mounts inside an E01, a partition, a decrypted volume or a file inside another filesystem, with no extra work.

Declarative UI

Publish commands (with icons and enablement), typed recovery options, map legends and structure views. The shell renders a contextual ribbon tab, an options grid, drive-map layers and Inspector sections for them.

Honest by contract

Statuses are part of the API: a read returns its sector statuses, and a failed decode is an error, never zeros. The test kit's conformance bases and corruption injector check this for your module.

A module in outline

[assembly: InVitroModule(typeof(MyContentModule))]

public sealed class MyContentModule : IContentAnalyzerModule
{
    // Declare what you want to see (sizes, types, header only or the whole stream);
    // the content pass hands you each file's bytes as ordered chunks, with any unreadable gaps
    // and their statuses, and you push attributes, digests and findings to a sink.
}
  • Modules depend on the public Core contract only, and are found by the capabilities they implement, never by name.
  • The contract is versioned, and the loader checks that a module was built for a compatible version.
  • Third-party modules load in the Complete edition.
  • Every module kind has a guide and a sample module in the API reference (see Docs).

Questions about the SDK or partnering on a format: support@invitroforensics.com.