Order now, get quotes

Upgrades/Renewals
 
Products
 
Find out more about X-Ways Forensics X-Ways Forensics
Integrated computer forensics software
 
Find out more about X-Ways Investigator X-Ways Investigator
Investigator version of X-Ways Forensics
 
Find out more about WinHex! WinHex
  License types
  Upgrade
  Forensic features
  All features
 
Find out more about X-Ways Imager X-Ways Imager
Disk imaging
 
Find out more about X-Ways Capture X-Ways Capture
Seize evidence
 
Find out more about X-Ways Trace X-Ways Trace
User activity
 
Find out more about Davory Davory
Data recovery
 
Find out more about X-Ways Security X-Ways Security
Permanent erasure
 
Services
 
Training
 

 
Contact X-Ways Contact X-Ways
User forum
 
Corporate info Corporate info
Find us on Facebook Find us on Facebook
  X-Ways Software Technology AG  
 
 

Data Analysis in WinHex

This page is to demonstrate how you can recognize the type of unknown data, e.g. in recovered files without their real name (as created from lost cluster chains by ScanDisk, Norton Disk Doctor, etc.) or when examining hard disk sectors, by sole use of visual representations. Using the data analysis feature of WinHex, you will note that certain file types have their characteristic byte value distribution, by which they can be identified. The following sample screenshots are hopefully self-explanatory:

JPEG

BMP

WAV

ZIP

EXE

TXT