Some of the key features of Physical Analyzer are highlighted above. The DB Viewer is where you can carve for deleted artifacts and BLOBs hidden inside of databases while the SQLite Wizard is where you can draft queries. There are built in viewers for plists, xml and protobuf files. Data carving is available upon parsing and after loading the data. Keep in mind that some carving features must occur while parsing. The timeline view is useful when trying to decide when an event occurred. Finally, the “Go to” lets you jump from artifact results straight to the timeline.
The
View menu option allows the user to easily navigate to the welcome screen to
navigate between projects.
The
View menu also allows the user to open a Trace Window, which opens a log of all
the operations and actions performed by the software on the data extraction so
that the examiner can know what is going on behind the scenes.
The Plug-ins menu option allows the user to Add/Remove Plug-ins by displaying a list of pre-installed plug-ins and allowing the user to manage them by adding or removing them from the list. Also in the Plug-ins menu is the Run Plug-in option, which enables the examiner to select and run one or more specific pre-installed plug-ins against the active data. The Chain Manager option in the Plug-ins menu displays the Chain Manager window and allows the user to create and edit device-processing chains, which essentially consist of multiple plug-ins run in a determined order.