Features
What the current build opens and what it does with it. The editions table shows which edition includes each part.
Formats
- Filesystems 17
-
- NTFS
- FAT12, FAT16, FAT32
- exFAT
- ext2, ext3, ext4
- HFS+
- APFS
- XFS
- Btrfs
- ZFS
- ReFS 3.x
- F2FS
- UFS1, UFS2
- ReiserFS
- UBIFS
- JFFS2
- ISO 9660 with Joliet and Rock Ridge
- UDF
Folders are listed straight from the volume, so you can browse before the full tree has been built. Checksums are verified on read for Btrfs, ZFS and ReFS. APFS encrypted volumes mount with their file data marked encrypted. UBIFS and JFFS2 are read from MTD dumps; raw NAND dumps with spare areas are not supported.
- Image containers
-
- Raw and split raw
- E01 (EWF)
- AFF4
- VHD, VHDX
- VMDK
- VDI
- QCOW2
- DMG (unencrypted UDIF)
.ivi- cue/bin, CloneCD, NRG, ISO
A split set with a segment missing still opens; the missing range reads as unavailable. A folder of loose files can be added as logical evidence.
- Partitions and volume managers
-
- MBR
- GPT
- Linux LVM2
- Windows dynamic disks (LDM)
- BSD disklabels
- UBI
Multi-device Btrfs and ZFS pools are assembled by their filesystem modules. RAID assembly is coming as a separate add-on and is not part of any edition yet.
- Encryption and snapshots
-
- BitLocker
- LUKS1, LUKS2
- F2FS per-file encryption
- Volume Shadow Copies
FileVault and encrypted DMG are not supported yet.
- Nesting
-
Every layer becomes a drive, and detection runs again on it. Tested combinations include a VHDX holding GPT holding NTFS, FAT32 and exFAT; LUKS2 holding ext4; E01 and QCOW2 holding ext4. A disk image found as a file inside a filesystem opens as a drive in place.
Imaging
- Physical disks, single partitions, USB and flash media, to raw (dd) or
.iviwith the per-sector read map and hashes. - Multi-pass reading, skip on error, retries, pause and resume. A Failing HDD profile sets these in one click.
- ATA SMART, NVMe health, HPA and DCO, read through an allowlist of read-only commands.
- ddrescue mapfiles in and out.
- Verify an image against its stored hashes.
Optical discs
- CD, DVD and BD: every session and track, including tracks missing from the table of contents.
- Raw CD reads keep subchannel data and C2 error pointers, with retry passes.
- Export to CloneCD, cue/bin, ISO and WAV.
Validated on a simulated drive built from real disc images. See Validation.
Browsing and viewers
Case tree
Evidence, partitions, layers and volumes in one tree. Selecting a node gives it a ribbon tab with the commands its module provides, such as Use FAT 2, Compare FAT copies or Scan MFT records.
Hex and structures
Each decoded field of a boot sector, superblock or record has a Go button that jumps to its bytes. A gutter shows the read status of every row.
Drive map
Read status, partition candidates and the regions modules paint, such as $MFT, $LogFile and used or free clusters, at any zoom, with an entropy layer.
Recovery
- Deleted files in place, plus orphans and lost-and-found. On FAT and HFS+, files whose clusters were reused are flagged.
- Partition recovery that finds volumes from their own metadata and validates each candidate before you adopt it.
- Carving over a node, a sector range or unallocated space only, with structure checks, fragment gluing for JPEG, MP3, MPEG and ZIP, and a verdict per file. Carving pauses and resumes, also after a restart.
- For each volume, the metadata copy to read from (FAT1 or FAT2,
$MFTMirr, backup superblocks, ZFS uberblocks, APFS checkpoints) is chosen automatically, the reason is recorded in the case, and you can switch it. - Compressed streams that fail to decode are reported as failures, never zero-filled.
- Export with a manifest.
Forensic analysis
Hashing
MD5, SHA-1, SHA-256, ssdeep and TLSH. Hash sets with NSRL and VICS import. One content pass reads each file once and feeds hashing, type detection, the index and YARA together.
Search
Keywords, patterns and regular expressions over raw sectors or file contents, in several encodings, plus an index for repeated searches.
YARA and Sigma
YARA-X rules over files; Sigma rules over Windows event logs. Each match links to its file, its bytes and its place on the timeline.
Windows artifacts
Registry, event logs, LNK, Prefetch, jump lists, the USN journal, SRUM, WebCache, shellbags, Recycle Bin and scheduled tasks, each linked to its source.
Documents and mail
PST, MSG and EML; OLE2 and OOXML Office files with macros flagged; PDF, SQLite, ESE, plists and EXIF. ZIP, 7z, RAR, TAR and CAB expand inline.
Timeline and gallery
A case-wide timeline, a picture gallery with visual-similarity search, and tags, bookmarks and notes from every view.
Decryption
- BitLocker: password, recovery key,
.bekfile, VMK or FVEK. - LUKS1 and LUKS2: passphrase, key file or master key; PBKDF2 and Argon2id.
- Try a list of known passwords against a volume.
- Keys are stored in the case, so volumes unlock again when the case is reopened.
InVitro does not brute-force passwords. It exports hashes in Hashcat and John the Ripper formats for BitLocker, LUKS and ZIP, and reads a Hashcat potfile back to unlock.
Reports
- Templates: full case, evidence summary, checked items and timeline extract. Sections switch on, off and reorder, with a live preview.
- HTML, PDF and CSV; hash lists; checked items exported with a manifest.
- Report packages (
.ivrep) carry findings between cases. A package made from different evidence is refused, with the reason. - A headless command line creates or opens a case, adds evidence, runs a processing profile, writes the report and exits with a status code.
Modules
Every container, partition scheme, decryption layer, filesystem, file type and content analyser in InVitro is a module on one public contract. A module declares its commands, options, map regions and structure views, and the application builds its ribbon tab, options and Inspector sections from them. Third-party modules load in the Complete edition. Developers.













