Home page
Emergency Help
Evolution of Forensic Computing
Evidential Hardware
Evidential Software
GenX
GenText
GenTree
Computer Electronic Disclosure
Training
Literature Requst
Investigation Services
Laboratory Services
Computer Forensic Systems

GenTree Investigation Software

Power and Performance
GenTree is a state-of-the-art product, developed over many years by our team of in-house software engineers. It is used on a daily basis by our computer investigation team. It is also used by Government organisations worldwide.

Major features are:

  • 32bit application – modern, efficient and user-friendly.
  • High-performance – maximises the benefit of modern machines.
  • Extremely fast file and word search times – gigabytes of data can be searched in seconds.
  • Extensive range of file viewers.
  • Full range of utilities for fast low-level interrogation.
  • Seamless handling of different file systems – see GenX.
Efficient and rapid investigation of an image requires initial powerful, accurate and speedy processing of the image file content. This is achieved by first running GenX and GenText to prepare the image content. GenTree is then used to perform the investigation.

What does GenTree do?
GenTree is a very powerful computer investigation tool for the serious computer investigator. It has an Explorer-type interface, which allows full access to all the processed data produced by GenX and GenText. The file system data is organised into separate directory views for easy navigation and management. Within each view the original directory structure from the original disk is retained.

Map on Demand
If an image is to be investigated as a matter of urgency, GenTree can be pointed at an image file and the image mapped (processed) as the directory tree is navigated. This means that:

  • No previous processing is required
  • Database is automatically built whilst navigating directory tree
  • Viewing of different file systems is seamlessly handled (dependent upon GenX modules enabled).
  • The user can swiftly view all files within each volume within the image
 

File Viewers
A variety of viewers is essential when performing an investigation. GenTree has a very wide range of viewers, to allow files to be examined in various ways and at all levels:

  • Original viewer (like original application)
  • Raw viewer (every byte within the file plus sector and cluster boundaries)
  • Raw viewer – filtered (like Raw but only textual data returned)
  • Typed viewer (typed text only)
  • Sector view (each sector for the file)
  • Thumbnail view (ideal for graphic files)
  • Slideshow (again, ideal for graphic files)
  • Launch (to launch an associated application) ***
Sector View
 

Word Search Engine
The GenTree search engine is second to none. It takes only seconds to search gigabytes of data – and obtaining fast results can often be crucial during the course of an investigation. Complex queries can be easily built and the many filters and features ensure that searches can be tailored to specific requirements. Time-consuming brute force searching is not required.

Filters include:

  • File name
  • File type or category
  • File date and time stamps
  • File system areas
  • Boolean operators
  • Substrings
  • Wordstems
  • Soundex ("sounds like")
  • Case sensitivity
  • Accent sensitivity

Features include:

  • Word dictionaries
  • Saving of search queries
  • Comprehensive and clear search results
  • Saving of search results
  • Reloading of search results
  • File tagging
…and a host of other management options.

Word Search Results
 

Flexibility and Control
A vast number of other options are available which are invaluable during the course of a computer investigation:

  • Logical sector searching (sector-by-sector string search).
  • Data trawl (retrieves files from deleted partitions, high-level formatted drives, free space, unused areas of the disk).
  • Cluster mapping (shows volume cluster usage and file positioning).
  • Timeline analysis (for analysing file movements across a time span).
  • Printing and exporting options.
  • Numerous copying options – including CD output options ***
  • Hashing options (for grouping files/directories for inclusion/exclusion).
  • Flat and hierarchical directory views.
  • Tag list management.
*** Viruses: If the "Launch Application" viewer is used or "Copying", the associated files are extracted "live" to a local disk or network. Warnings are given regarding the need to virus scan these files, however it is the responsibility of the user to perform virus scanning.

Investigation Services
Computer investigations must be carried out by professionals who are experienced both with the Law and IT. Our highly experienced in-house Investigation Services Team are all government trained specialists and are available to assist with all levels and types of computer investigation, including high-level sophisticated fraud, email/Internet abuse, intellectual property theft, downloading of inappropriate material etc.

UK +44 (0) 1869 355255
Freephone 0800 581263
investigate@vogon.co.uk USA +1 405 321 2585
Toll Free 1-800 392-5373
investigate@vogon.us
München +49 (0) 89 3235030
Köln +49 (0) 2203 91547 400
Freecall 00800 42424200
investigate@vogon.de Norway +47 2337 1400
Freecall 00800 42004242
etterforskning@vogon.no

Copyright Vogon International. All rights reserved.  
Home Page | Investigation Services | Laboratory Services | Forensic Systems