Documentation
Manual and API reference
The user manual ships with every installation: press F1 or open Help. Both the manual and the API reference are published on this site at release.
User manual
For examiners and recovery technicians.
- Getting started: cases, adding evidence, the screen layout
- Acquisition: disks, partitions, flash and optical media; retries and resume; raw and
.iviimages and read maps - The case tree, module commands and options
- Browsing, preview, hex and structure views, the drive map and the status colours
- Recovery: deleted files, lost and found, partition recovery, carving, optical data outside the file tree
- Decryption and keys; Hashcat and John the Ripper export
- Hashing, the content pass, YARA and Sigma, search, artifacts and the timeline
- Reports, the command line, troubleshooting and a glossary
Published at release
API reference
For module authors and automation.
- The module contract and how versions stay compatible
- Drives, node maps and sector statuses
- Probes and confidence, result sinks, commands, options, map legends and structure views
- Guides for each module kind: containers, partitioning, layers, filesystems, file types, analysers, content analysers and volume versions
- The test kit and conformance bases; packaging and installing a module
- Reference pages generated from the public API
Published at release Developers overview →
Command line
InVitro runs a processing profile on a case without the main window: it creates or opens the case, adds evidence, runs the profile, writes the completion report, and exits with a code that says how it went.
InVitro.exe --case new:D:\cases\Example --add E:\evidence\disk.E01 --profile Triage --report evidence-summary --out D:\out --exit
Available in the Forensic and Complete editions. The full switch list is in the manual.