Documentation
The user manual ships with the program: press F1, or open Help. The manual and the API reference will also be published here at release.
User manual
- Cases, adding evidence and the screen layout
- Imaging disks, partitions, flash and optical media; retries and resume; raw and
.iviimages and read maps - The case tree, module commands and options
- Browsing, preview, hex and structure views, the drive map and the status colours
- Deleted files, lost and found, partition recovery and carving
- Decryption, stored keys, and Hashcat and John the Ripper export
- Hashing, the content pass, YARA and Sigma, search, artifacts and the timeline
- Reports, the command line, troubleshooting and a glossary
API reference
- The module contract and how versions stay compatible
- Drives, extent maps and sector statuses
- Probes, result sinks, commands, options, map legends and structure views
- A guide and a sample for each module kind
- The test kit, conformance tests, and packaging a module
- Reference pages generated from the public API
Command line
InVitro can run a processing profile without opening its window: it creates or opens the case, adds evidence, runs the profile, writes the report and exits with a code that says how it went.
InVitro.exe --case new:D:\cases\Example --add E:\evidence\disk.E01 --profile Triage --report evidence-summary --out D:\out --exit
Forensic and Complete editions. The manual lists every switch.