·.·. Computer forensics software made in Germany .·.·

Data Analysis in WinHex

This page is to demonstrate how you can recognize the type of unknown data, e.g. in recovered files without their real name (as created from lost cluster chains by ScanDisk, Norton Disk Doctor, etc.) or when examining hard disk sectors, by sole use of visual representations. Using the data analysis feature of WinHex, you will note that certain file types have their characteristic byte value distribution, by which they can be identified. The following sample screenshots are hopefully self-explanatory: