Link | OSForensics | ProDiscoverBasic | WinHex | R-Studio | Active@FileRecovery | Active@Undelete | Recuva | Autopsy | FTK Imager |
---|---|---|---|---|---|---|---|---|---|
Static acquisition | Yes | Yes | Yes | Yes | Yes | Yes | No | - | Yes |
Live acquisition | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Remote acquisition | No | No | No | Yes | No | No | No | No | No |
Physical data copy | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes |
Logical data copy | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes |
Data acquisition formats | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Command-line process | Yes | No | No | No | No | No | No | Yes | No |
GUI process | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Case managment | Yes | Yes | No | No | No | Yes | No | Yes | No |
Verification | Yes | Yes | Yes | No | Yes | Yes | No | Yes | Yes |