After this point, you must select "Images" from the tree view, and then right-click the file and click on "Add. Once the start screen has been loaded, you can then move onward to pressing on the "Open" button. Once you've downloaded and installed ProDiscover, and of course obtained your disk image through the methods explained simply start ProDiscover and follow the next steps.
In order to obtain a copy of ProDiscover you should visit the following web location: ProDiscover and if you want to follow along to the files that are displayed in explorer and the files that the forensic software sees, you may download PassMark OSFMount.įinally, if you need to procure a forensic image and make sure the image is sound please review this resource: Obtain Disk Image With Linux as it will guide you through the process to forensically obtain a disk image, verify the image and make sure you are not writing to the device itself. The first thing that we will mention is that you will have to download, or order a copy of ProDiscover before you can begin going down this route.
Although this is an older version it may in fact be the same in the newer versions - if however, it is not we will attempt to get a newer version of ProDiscover in order to demonstrate the use of the software in another article.
The main purpose of this document is for forensic file recovery with ProDiscover. This article covers information regarding ProDiscover Forensic tools to retrieve files from a computer whose data has been destroyed.