Build a module, get the whole UI
Everything in InVitro that reads evidence is a module: the built-in filesystems use the same public contract you do. Write the format logic. The case tree, ribbon, options, drive map and Inspector come with it.
| Module kind | Recognises | Produces |
|---|---|---|
| Container | An image file or segment set | One drive |
| Partitioning / volume manager | A disk | One drive per partition or volume |
| Layer | An encrypted or transformed volume | One drive with the decoded content |
| Filesystem | A volume | A file tree; every file opens as a drive |
| Volume version | A filesystem's snapshots | Browsable earlier versions |
| File type and analyser | A file | Previews, metadata, timeline events, artifacts |
| Content analyser | Each file's content, streamed once by the content pass | Attributes, findings and digests |
Everything is a drive
A module never opens a path or a device. It reads a drive through an extent map, so whatever you write mounts inside an E01, a partition, a decrypted volume or a file inside another filesystem, with no extra work.
Declarative UI
Publish commands (with icons and enablement), typed recovery options, map legends and structure views. The shell renders a contextual ribbon tab, an options grid, drive-map layers and Inspector sections for them.
Honest by contract
Statuses are part of the API: a read returns its sector statuses, and a failed decode is an error, never zeros. The test kit's conformance bases and corruption injector check this for your module.
A module in outline
[assembly: InVitroModule(typeof(MyContentModule))]
public sealed class MyContentModule : IContentAnalyzerModule
{
// Declare what you want to see (sizes, types, header only or the whole stream);
// the content pass hands you each file's bytes as ordered chunks, with any unreadable gaps
// and their statuses, and you push attributes, digests and findings to a sink.
}
- Modules depend on the public Core contract only, and are found by the capabilities they implement, never by name.
- The contract is versioned, and the loader checks that a module was built for a compatible version.
- Third-party modules load in the Complete edition.
- Every module kind has a guide and a sample module in the API reference (see Docs).
Questions about the SDK or partnering on a format: support@invitroforensics.com.