Description: X-Ways Forensics is an advanced work environment for computer forensic examiners and our flagship product. It runs under Windows 2000/XP/2003/Vista*/2008*/7*, 32 Bit/64 Bit. Compared to its competitors, X-Ways Forensics is more efficient to use after a while, often runs faster, is not as resource-hungry, finds deleted files and search hits that the competitors will miss, offers many features that the others lack, ..., and it comes at a fraction of the cost! It is based on the WinHex hex and disk editor and part of an efficient workflow model where computer forensic examiners share data and collaborate with investigators that use X-Ways Investigator.
source : http://www.x-ways.net/forensics/
This video is simple demo of how to cover a directory and its children in some forensics way rather than simply copying and pasting the files. this ensure capturing of hash files,full paths etc.
Disclaimer: We are a infosec video aggregator and this video is linked from an external website. The original author may be different from the user re-posting/linking it here. Please do not assume the authors to be same without verifying.
X-Ways And Winhex Great Tools. one of the best part is live Ram Analysis. You can also clone Live Ram. And after we can investigate.
this tool has ability to analyze remote computer also.