OnScene Investigator Software

OnScene investigator software is built for first respondents to a scene or for anyone who needs to quickly review or copy information on a suspect computer. OnScene investigator requires the boot CD, OnScene investigator client and a crossover cable.
The software is a cost effective, simple to use tool for quickly searching and/or imaging computers (in Encase format). It's ideal for on scene triage of computers to identify relevant evidence before imaging. Suitable for all PCs, especially Apple Macbook and Macbook Pro.
- Viewing the contents of the internet cache in thumbnail view.
- Copying the suspect's index.dat for review in X-Ways Trace or Digital Detective
- Copying the suspect's mail file for review in an email investigation software such as Paraben's Email Examiner.
- Searching for keywords on a suspect computer before proceeding to imaging.
OnScene Investigator and OnScene LHF are rapid ways to complete common tasks undertaken by Computer Forensics Experts. The tools are focused on being as simple as possible to use.
OnScene Investigator is a tool for “having a quick look “at a suspect’s computer. OnScene Investigator, we believe is a time saver and worth its place in any computer forensic expert’s or IT admins tool kit.
System requirementsOnScene Investigator:
• PC-compatible machine
• 32 MB RAM
• Standard network port
• Onscene Investigator & OnScene LHF system require less then 10 MB of space and can run from a USB drive.
• Operating systems: Windows 2000/XP/Server 2003/Server 2008/Vista
(x32 and x64)
Can be logged to Windows without administrative privileges.
OnScene LHF

Open and reports:
- NTUSER.dat, HKCU, HKLM, SOFTWARE SYSTEM registry hive.
- All USB devices that have been connected.
- The user's internet history.
Other Features:
- Custom configurable for software license audits.
- Captures registry Low Hanging Fruit (LHF) at the click of a button.
OnScene LHF is designed to do 80% of the common tasks in 20% of the time of current solutions. At the click of a button you can enumerate 195 registry keys and the internet history of a suspect, leaving you the time to focus on the evidence and not having to remembering what registry hive contains the USBSTOR information.
OnScene LHF:
• PC-compatible machine
• 32 MB RAM
• Standard network port
• Onscene Investigator & OnScene LHF system require less then 10 MB of space and can run from a USB drive.
• Operating systems: Windows 2000/XP/Server 2003/Server 2008/Vista
(x32 and x64)
Can be logged to Windows without administrative privileges.
No drivers, no special installation!