“… The results were extremely impressive. It showed the suspect using [a website] to download illegal content and also showed the actual folders on his desktop. Makes proving this case really easy.”
Cyber Crime Investigator, Durham Constabulary, UK
In some cases, an experienced investigator can manually create a virtual machine from a forensic image. However, this can be time-consuming and error-prone task. VFC automates the process and applies over 10 years of acquired knowledge to fix numerous potential issues and quickly produce a compatible and stable virtual machine in seconds. VFC removes the guesswork from virtualisation and allows the investigator to concentrate on the investigation:
Reliably and quickly create a VM from either forensic image or write-blocked physical disk with just a few mouse clicks
Avoid common virtualisation errors due to BSOD and incompatible drivers
Avoid accidently changing original evidential material
Bypass Windows account passwords including Windows 8/10 “live” account passwords
Access encrypted disk data such as Bitlocker (requires recovery key or similar)
Experience the original user desktop and take screenshots or video of key evidence items for use in court:
Interact with installed software in its native environment and access evidence that could otherwise be unavailable:
Interact with original connected devices such as:
Amend VM hardware to match the original hardware by adding additional disk/images, sound, USB or network support (disabled by default)
Repair broken VMs following Windows System Restore or similar
Generate standalone VM for use by non-technical staff and other investigators
Heavy investment in R&D and regular updates
Full UK based telephone and email support based
Please see the VFC FAQ for further information.