Digital forensics

Acquire, analyse, report, and seal it.

A recovery engine and a forensic toolkit in one product. It images read-only, hashes every acquired and exported item, keeps a hash-chained audit trail, seals the examiner’s reading before any model answers, and produces a report that carries the method and the evidence alongside the conclusion, with a draft certificate under Section 63(4) of the Bharatiya Sakshya Adhiniyam 2023.

SakshyaYantra Forensic Suite

Built to the rules an examiner is held to.

The frame pack is the only unit that leaves the machine. The three times, presentation, overlay and case, are never merged. The examiner's reading is sealed before any model answers. Enhanced is shown beside the original, never instead of it. The certificate is drafted under S.63(4) of the Bharatiya Sakshya Adhiniyam 2023.

SakshyaYantra Enterprise 20.54.3.2
SakshyaYantra Forensic Suite: video review with presentation time, overlay text and case time as separate fields
The forensic workflow

Every stage leaves a record.

Write-blocked imaging

Image any source to E01 or raw dd, source read-only and fingerprinted before and after.

Verified hashing

SHA-256 on every acquired and exported file, recorded in a manifest.

Hash-chained audit

Every action commits to the one before it; the trail names the first break.

Chain of custody

The source offset of every recovered file: which sectors of the exhibit this is.

OS artefacts

Recycle Bin, USN, prefetch, registry, LNK, event logs, ShellBags, AmCache, SRUM, plus macOS.

Memory forensics

Processes, sockets, modules, handles and injected code from a RAM capture.

Video evidence

The recorder view, frame-exact review, the three times kept separate, and the per-frame frame pack.

The certificate

A draft certificate under S.63(4) BSA 2023, always marked DRAFT until a reviewer signs.

Chain of custody

Nothing unaccounted for.

A recovered file carries its SHA-256, its source offset, and the mode it was recovered in. The audit trail is hash-chained, so a single edited line is caught.

Acquire

Write-blocked image, hashed on the way in, source verified unchanged over the regions a stray write would touch.

Analyse

Recover, carve and pull artefacts from the image, never the original, every result traced to a source offset.

Attest

A dated report in PDF, Word or HTML, with the hash-chained trail sealed so truncation is caught too.

The honest line

Modelled on the NIST CFTT method and says so. A rigorous self-validation, not a NIST accreditation.

The whole estate

The same bench, on every endpoint.

The Forensic Suite carries an agent for the machines: sweep the estate for a filename, an exact SHA-256 or a string inside files, acquire a machine that cannot be switched off with its volume frozen at one instant, and queue the laptops that are away, with everything on this page underneath, in the same build. Enrolment is report-only by construction; the server cannot instruct an agent.

SakshyaYantra Forensic Suite 20.54.3.2
SakshyaYantra Forensic Suite: the super-timeline across artefacts

Produce a case file that carries its own evidence.

Image, hash, analyse, seal and report with one tool, fully offline. Or hand the exhibit to our lab.