HexView
Use this function to examine internal file system metadata. Templates are provided to decode some common metadata structures such as boot sectors, NTFS master file table, etc.
Device
The drive or disk image being examined.
Navigator
||<<
Go to the first sector.
<<
Go to the previous sector.
>>
Go to the next sector.
>>||
Go to the last sector.
Number of sectors to read.
History of Go to sectors.
Sector to display if Go is clicked.
Go
Go to the sector number in the textbox on the left.
Search... Search for data at a specific sector offset.
Offset in HEX
Byte offset into the sector of the field being searched.
First sector
Search from this sector.
Last sector
Search to this sector.
Search content in HEX
Value to search for in hexadecimal format.
Next
Search for the next value.
Next non-zero
Search for the next non-zero value at the specific sector offset.
Template
Many templates are available to decode the sectors being displayed.
After choosing a template, you can choose a field containing an offset and right-click to display the Go to dialog to go to the offset.
Use this for the next display
Check this box to use the same template to decode subsequently displayed sectors. Use this option to examine consecutive structures in the same format such as FILE records in an NTFS MFT table.
Copyright © 2017-2026 QueTek Consulting Corporation. All rights reserved.
Back to Table of Contents
|