Home |  Log In  
Forensics and eDiscovery technologies for Mac OS X, Microsoft Windows, and Linux

13: Hash functions for files and devices

This section will describe the hash function contained within MacForensicsLab.

Using the Hash Function
Using the Hash function.

The Hash functionality is a new feature added in MacForensicsLab 3.0. This button allows the examiner to quickly and easily create a hash of any device or file by highlighting it (1) and invoking the "Hash" button (2).

Reviewing the Hash
Reviewing the Hash.

Once completed, the Hash window appears. The hash values are displayed in two separate fields. The first shows the hash data presented in a form for better human readability. The second field shows the raw hash data. Both contain the same information, just formatted differently for interoperability and readability.

Saving the Results
Saving hash results.

The results of the hash can be either saved out as a text file by clicking the Export button or added directly to the hash database. To export, simply select the formatting of the has you could like the export using the radio button, click "Export" and navigate to where the file is to be saved. To add the hash data to the database, select the database section from the drop down menu and click the “Add” button.


 | Home | 

Copyright © 2006 - 2010 MacForensicsLab Inc.
Phone +1 (510) 870-7883 - Fax +1 (510) 868 3407
Mac and the Mac logo are trademarks of Apple Computer, Inc., registered in the U.S. and other countries.

Forensics Technologies - designed to perform investigations, for law enforcement and eDiscovery professionals.

MacForensicsLab - The only effective cross-platform weapon in the war on Cyber Crime and Digital Terrorism,
with unique tools designed to combat identity theft and child pornography.