This is a collection of utilities and libraries intended for forensic or forensic-related investigative use in a modern Microsoft Windows environment. The components in this collection are intended to permit the investigator to sterilize media for forensic duplication, discover where logical volume information is located and to collect the evidence from a running system while at the same time guaranteeing data integrity (e.g. with a cryptographic checksum) and while minimizing changes to the subject system. The present release attempts to reduce the time required for volume or drive imaging by reducing, if not eliminating, the need for piping and by incorporating cryptographic verification into the imaging application.