SakshyaYantra, digital forensics

The computer-forensics bench

Disk examination in one console: acquire or ingest an image, build the case, and examine it - a combined timeline, memory, hash sets, keyword lists and YARA, with mailbox and database salvage. The case opens across the SakshyaYantra family, sealed with the chain of custody.

Licensed by a key bound to one machine, sold by the drive or image.

Who it is forComputer-forensics examiners and digital-forensics laboratories - the bench a lab would otherwise run on EnCase, FTK or X-Ways.
SakshyaYantra Examiner: the objects it works on, rendered in the family colour
The workspace it is bought for

SakshyaYantra Examiner, as shipped

A real screenshot of version 20.54.3.2, captured from the shipping build on this bench. Nothing on the site is a mock-up.

SakshyaYantra Examiner 20.54.3.2
SakshyaYantra Examiner screenshot
Typical cases

What this product is bought for

If the situation below matches yours, this is the right product. If none of them do, another product in the range is likely to be a closer fit, and the last section on this page says which.

A disk image has been acquired and the examiner needs the whole computer-forensics bench - artefacts, memory and a timeline - in one console.

An investigation needs an ordered account of what happened on a machine and when, with the chain of custody carried from acquisition to the report.

A known-file hash set, a keyword list or a YARA rule set has to be run across an exhibit and the hits carried into the case.

A mailbox or a database is part of the evidence and has to be salvaged and read, not just listed.

Key points

How SakshyaYantra Examiner is built

The engine that acquires it also examines it

Imaging and recovery run here in forensic mode - hashed, manifested, read-only on the source - so an image is acquired and examined in the same build, not handed between tools.

One combined timeline

$MFT and $LogFile records, Windows, Linux and macOS artefacts, and file-system times are merged into a single ordered sequence, each entry carrying where it came from.

Sealed into a shared case

The case opens here as it does across the four products, and the findings, the report and the draft Section 63(4) certificate are drawn from the case's own records.

Capabilities

What SakshyaYantra Examiner does

Verified acquisition and ingest

Raw, E01, Ex01 and AFF4 images, hashed on read and verified on completion, or an image another rig produced ingested and normalised, with a software write block where supported.

Artefact analysis

Windows event logs, registry, Prefetch, ShimCache, BAM, SRUM, Jump Lists, LNK, Recycle Bin, browser history and Windows Timeline, plus Linux and macOS artefacts.

Memory analysis

Process lists, network connections, loaded modules, handles and injected-code detection from a memory image.

Hash sets, keyword lists and YARA

Classify known files against a hash set, run keyword lists across the evidence, and match YARA rules, with the results carried into the case.

Mailbox and database salvage

Outlook PST and OST, Exchange EDB at table level, mbox, Maildir and EML; page and row extraction from SQL Server, MySQL, PostgreSQL, Oracle, MongoDB, Access and SQLite, deleted rows included.

Vehicle, drone and robot black-box readers

Infotainment and event-data records, DJI flight logs and .SRT telemetry, and FANUC, KUKA and ABB controller logs, read for the case with a hashed manifest of the source.

Steganalysis

The evidence is checked for data hidden inside carrier files, with the method and its result recorded in the case.

Workspaces in this build

These are the workspaces the application contains. Anything not listed is absent from the build; it is not present and locked behind the licence.

  • Forensic examination and reporting
  • Case hub: cases, versions and locks
  • Foreign image and dump ingest
  • Evidence viewer
  • Detect every connected device, with a report
  • Cross-case lookup
  • Ask the case (AI observations after a sealed reading)
  • Recover files from disks, cards and images
  • Image a failing drive
  • RAID and storage-pool reassembly
  • Chip-off and rig-dump reconstruction
  • Memory (RAM) analysis
  • Mailbox recovery (Outlook PST/OST, mbox, Maildir)
  • Database row extraction
  • Steganalysis
  • Timeline across artefacts
  • Link analysis
  • Known-file hash sets
  • Indexed keyword search
  • YARA scanning
  • Vehicle data recovery
  • Drone flight log and video telemetry recovery
  • Industrial robot and controller incident data

The rest of the range

This page lists what the product does. Each product in the range is built for its own job, and what every one of them does is set out, product by product, on the products page, generated from the build itself. Hardware cases (drives that do not spin, locked phones, encrypted volumes) are covered in the hardware help guide.

What each product does

Partner access

Get SakshyaYantra Examiner

Disk examination in one console: acquire or ingest an image, build the case, and examine it - a combined timeline, memory, hash sets, keyword lists and YARA, with mailbox and database salvage. The case opens across the SakshyaYantra family, sealed with the chain of custody.

Get SakshyaYantra Examiner

Supplied to approved RecoverYantra partners. Apply once; your dashboard then carries every product, the licence keys for your machines and a direct line to our engineers.

Become a partnerTell us about your business. Applications are reviewed by a person, and you will hear from us by email.
Apply for access
Already a partnerSign in for the current build, your keys and support.
Partner sign in
Version 20.54.3.2Windows 10 or 11, 64-bitRead-only against your drives

System requirements

  • Windows 10 or 11, 64-bit
  • Administrator rights to read a physical drive. Working from a disk image needs none.
  • A separate destination with room for the recovered data. Results are never written to the drive being read.

Linux

The engine runs on Linux from source, and a Linux command-line build is available on request.

Specifications

SakshyaYantra Examiner at a glance

Every row is read from the build this page was generated from.

ProductSakshyaYantra Examiner, version 20.54.3.2
FamilySakshyaYantra, digital forensics
PlatformWindows 10 and 11, 64-bit. Administrator rights are needed to read a physical drive; working from a disk image needs none.
Workspaces included23 of 42 in the range: Forensic examination and reporting, Case hub: cases, versions and locks, Foreign image and dump ingest, Evidence viewer, Detect every connected device, with a report, Cross-case lookup, Ask the case (AI observations after a sealed reading), Recover files from disks, cards and images, Image a failing drive, RAID and storage-pool reassembly, Chip-off and rig-dump reconstruction, Memory (RAM) analysis, Mailbox recovery (Outlook PST/OST, mbox, Maildir), Database row extraction, Steganalysis, Timeline across artefacts, Link analysis, Known-file hash sets, Indexed keyword search, YARA scanning, Vehicle data recovery, Drone flight log and video telemetry recovery, Industrial robot and controller incident data
File types recovered269 formats carried in the signature table, searched together with file system parsing.
Access to the sourceRead-only for the whole session. The application refuses a destination on the drive being read.
LicensingA signed key bound to this machine's code, verified offline. Sold by the source: one use is one drive or image, and the same source is free afterwards. No account, no activation server and no internet connection needed.
Before a keyScan, browse and preview without a key; the key is asked for when files are first saved from a source.
DependenciesNone to install. The forensic family bundles its own media and analysis libraries inside the installer; nothing is fetched at run time.
How it is suppliedThrough the partner programme. The build is 772 MB; its SHA-256 is shown beside the download in your partner dashboard.
Related products

Where the rest of the range fits

These products carry workspaces SakshyaYantra Examiner does not. The list is derived from the catalogue, so it cannot point at a product that lacks the capability too.