Tested against the truth, not against itself
A forensic tool is only as good as the evidence that it is right. Here is how InVitro is tested, what we publish, and how it supports your own method validation.
Real images, made by real tools
Test images are made by the systems that write those formats: Windows for NTFS, FAT, exFAT and UDF; the Linux kernel and its mkfs tools for ext, XFS, Btrfs, F2FS, UBIFS, JFFS2, ReiserFS and UFS; ewfacquire for E01; qemu-img for QCOW2; cryptsetup for LUKS.
Independent oracles
What InVitro reads is compared file by file and hash by hash with what an independent reader sees: Windows itself, the Linux kernel driver, or libewf for E01 images.
Corruption campaigns
Parsers are fed mutated and truncated copies of the real images. Damaged structures must be refused or flagged, never served as good, and a parser must never crash or hang. Every decoder has tests with input that is certainly corrupt.
What every status means
Statuses travel with the bytes into previews, hashes, exports and reports.
| Status | Meaning |
|---|---|
| Good | Read from the source, and verified where the format has a checksum. |
| Unreadable | The device or image could not return these sectors. |
| Checksum failed | Read, but the format's own checksum does not match. |
| Locked | Encrypted, and no key has been supplied yet. |
| Unrecorded or unavailable | Never written (for example, past the end of an optical session), or missing, such as a lost segment of a split image. |
A compressed or encrypted stream that fails to decode is reported as a decode failure. It is never filled with zeros and counted as recovered.
For your lab
Public validation pack
A downloadable set of test images in the style of NIST CFReDS and CFTT. Each image comes with the tool that made it, the expected outputs (file lists, per-file SHA-256, deleted entries, partition tables), InVitro's measured results and error rates, and the corruption-campaign results. The pack is updated with every release. Published at release
Standards
- SWGDE 18-Q-001. A matrix mapping each requirement for testing forensic tools to the test cases in the pack.
- NIST CFTT. We will request NIST testing for disk imaging, deleted file recovery and file carving, and publish our own runs of the CFTT procedures through Federated Testing.
- ISO/IEC 17025. A method-validation template (scope, test images, acceptance criteria, results) prefilled with our results, so your lab only adds its own runs.
Questions counsel asks (Daubert / FRE 702)
- Has it been tested? Yes: against independent oracles on real tool-made images, with published results.
- What is the error rate? It is measured per release and published in the pack, including how often damaged input was flagged rather than served.
- Are there standards? SWGDE requirements are mapped and ISO 17025 method validation is supported.
- What did the tool not read? Every unread or unverified sector is marked as such, so you can testify to exactly what was recovered.
Stated plainly
- Optical disc acquisition is validated on a simulated drive built from real disc filesystems (genisoimage, xorriso, mkudffs). Validation on live multisession discs is under way.
- Flash filesystems (UBI, UBIFS, JFFS2) are validated on clean MTD dumps. Raw NAND chip dumps with spare areas and ECC are not supported yet.