SMA-FAX2 is a powerful and comprehensive forensic analysis software designed for extracting, analyzing, and visualizing electronic evidence. It integrates evidence retrieval, forensic analysis, relationship mapping, and automated report generation into a single platform.
With its advanced filtering capabilities, users can quickly locate key information anytime, anywhere. The built-in one-click extraction feature enables efficient data retrieval from Windows, Mac, and Linux systems, as well as from memory and files. Designed for ease of use, SMA-FAX2 requires minimal technical expertise, making it an ideal tool for digital forensic professionals.
1. Multi-Format Support & Loading
Supports direct analysis of computer storage media and various disk image formats, including DD, IMG, 001, DMG, E01, and L01. Also compatible with virtual disk files such as VMDK, VHD, VDI, HDS, QCOW2, and VHDX, along with standalone directories and files.
2. Wide Compatibility & Partition Support
Supports local disks, optical drives, floppy drives, and external devices. Compatible with MBR and GPT partition schemes and file systems such as NTFS, FAT, exFAT, Ext2/Ext3/Ext4, HFS/HFS+, XFS, and APFS.
3. Automated Data Parsing
Provides five core modules: Windows, Mac, Linux, Memory File, and Live Forensics.
Windows: Covers 10 categories with 97 types of sensitive data.
Mac: Covers 10 categories with 63 types of sensitive data.
Linux: Covers 6 categories with 15 types of sensitive data.
Memory: Covers 4 categories with 14 types of sensitive data.
Live Forensics: Supports real-time extraction of 13 types of passwords, including system and email credentials.
Multi-OS Support
Capable of parsing system data, applications, and file systems from Windows, Mac OS, and Linux.
4. Browser Data Extraction
Supports analysis of over 10 popular browsers, including IE, Google Chrome, and Safari. Retrieves browsing history, cache, cookies, bookmarks, downloads, search records, and login email addresses.
5. Email Client Analysis
Supports comprehensive analysis of email clients, including Foxmail, Outlook Express (DBX), Office Outlook (PST, OST), Lotus Notes (NSF), and EML.
6. Application Analysis
Supports parsing of Windows ShimCache and Amcache data.
7. Compressed File Processing
Enables preview and analysis of compressed files in RAR, ZIP, and 7Z formats.
8. Office Metadata Analysis
Extracts key metadata such as document author, original creation time, last saved user, and internal modification timestamps.
9. Mobile Backup File Identification
Detects backup files from Apple and Android devices.
10. Mac System Parsing
Automatically extracts key data from Mac systems, including Keychain and FSEvent logs.
11. Intelligent Search & Filtering
Supports multi-keyword searches, wildcard matching, and automatic detection of sensitive data such as bank accounts, phone numbers, and ID numbers. Also enables case file search and dynamic filtering of results.
12. Photo & Video Preview
Displays image thumbnails in different sizes with a zoom function. Video files show their first frame for quick identification.
13. Registry Analysis & Report Export
Supports automatic registry file loading and web-based registry analysis reports.
14. Data Summarization & Statistics
Quickly compiles disk and sensitive data statistics for forensic investigations.
15. Custom Report Generation
Exports analysis reports in web format and customizable Word templates.
16. File Viewer Functionality
Supports viewing files using third-party tools, which can be added via a built-in management module.
17. RAID Disk Array Support
Analyzes HP dual-loop RAID and RAID1 disk arrays.
18. Standalone Data Upload & Cross-Referencing
Allows data upload and cross-referencing in the standalone version.
19. NTFS Disk Log Analysis
Analyzes USN logs, including file creation, modification, deletion timestamps, and change types.
20. Hexadecimal Auto-Decoding
Automatically deciphers hexadecimal results in sectors, files, and registry entries.
21. Time Decoding Tool
Includes a built-in tool for manually decoding numerical timestamp values.
22. Linux Virtual Machine Image Parsing
Supports parsing QCOW version 1, 2, and 3 virtual machine images.
23. HEIF Image Preview
Displays HEIF images captured by iOS 11 devices.
24. Virtual Machine File Parsing
Automatically loads and analyzes virtual machine files.
25. APFS File System Analysis
Supports parsing of macOS 10.13 APFS file systems and related applications.
26. MFT Record Parsing
Analyzes file MFT record numbers and update timestamps.
27. Partition Recovery
Supports intelligent and manual recovery of lost partitions. Detects DBR backup partitions in NTFS and FAT32 formats.
28. 4K Sector Hard Drive Analysis
Directly reads and analyzes 4K sector physical hard drives.
29. Email Analysis & Viewing
Offers attachment categorization, calendar-based email sorting, email address statistics, geographic analysis, map visualization, and cross-referencing functions.
30. Browsing History Analysis
Compiles browsing records based on website type and visit time. Allows manual categorization of websites.
31. User Activity Analysis
Generates daily statistics and charts for browsing, emails, chats, and file activities.
32. Call Log Analysis
Supports call record analysis for China Mobile, China Unicom, and China Telecom, including call frequency, calendar-based call logs, and duration statistics.
33. SQLite Database Viewing
Enables real-time viewing and searching within SQLite databases.
34. Report Viewer
Provides a built-in report viewer with an interface identical to the software’s main UI.
35. Registry Jump Function
Allows one-click navigation from analysis results to the corresponding registry entry.
36. File Classification Management
Supports over 1,000 file categories with a built-in management module for adding, modifying, and deleting classifications.