How does ProDiscover® Investigator work?
A. ProDiscover® Investigator uses the lowest level disk sector read commands to get data off the disk. It uses its own file system and GUI to display all the files on the system, including recoverable deleted files and Alternate Data Streams (these files are usually overlooked by other audit tools). The use of the low level disk sector reads and a separate file system prevents any files from being hidden from the investigator. Once all the data is exposed, the user can chose files or folders to be examined in more detail. The software automatically generates hash signatures of each file before examining the file. This guarantees data integrity can be proven if evidence is uncovered. In addition, the file type can be compared to the file extension to identify any mis-classified files (a trick used by many criminals to hide information). The suspect files can then be searched to see if they contain any proprietary, unauthorized, or inappropriate data. Finally, if any evidence is found, t