NetAnalysis® 4: Boost Your Digital Forensics with Advanced Browser Analysis
We are delighted to announce the release of NetAnalysis® v4.0, a major update that brings powerful new features, enhanced performance, and a refined user interface, all designed to help forensic examiners work faster and more efficiently. This release marks a significant step forward in browser forensic analysis, with a suite of advanced tools to support the evolving landscape of browser-based evidence.
Whether you’re examining thousands of cached images, deep-diving into client-side storage, or unravelling the structure of complex URLs, NetAnalysis® v4.0 gives you the tools you need to uncover the truth with clarity and precision.
Record View
The new Record View is a dockable panel integrated into the main form, providing a concise summary of key columns for the selected row. This feature enhances your ability to quickly assess and interpret data, streamlining your analysis process. As shown below, the panel displays critical information at a glance, allowing you to focus on the most relevant details without navigating through multiple windows.

Image Gallery
NetAnalysis® now includes an Image Gallery Viewer, a new thumbnail-based image viewer that makes it easy to browse, review, and manage cached images, preview thumbnails, FavIcons and more. With support for JPEG, PNG, SVG, WebP, GIF, BMP, and ICO formats, this grid-style viewer allows you to:
- View all recovered images in one place
- Tag, bookmark, and filter relevant images
- Export selected images for further investigation
Ideal for quickly assessing visual content and identifying key artefacts.

Storage Examiner
The new Storage Examiner brings deep analysis capabilities for Local Storage, Session Storage, and IndexedDB entries. With a structured view of client-side storage, you can:
- Search and filter JSON key-value pairs
- Decode and examine deeply nested data structures
- Export selected data to XLSX, CSV, PDF or text formats
This is a significant enhancement for anyone investigating modern web applications and single-page apps.

Examination and Analysis
The Examination and Analysis Form has been significantly upgraded with a suite of new decoders and analytical tools:
- The Decoded Text Tab now automatically detects and formats JSON, offering coloured text and code folding for improved readability.
- A dedicated JSON Examiner Tab allows for in-depth viewing and examination of JSON data.
- New decoders for Google URL VED Parameters, URL Dot Separated Values, Google Protocol Buffers in URLs, URL Query Parameters, and MIME-Q and MIME-B provide advanced capabilities for performing analysis on URL components and encoded data.
- Hashing tools for MD5, SHA-1, SHA-256, SHA-384, SHA-512, and RIPEMD-160 have been added, along with viewers for URL search Query Parameters and URL Components, making this a comprehensive toolkit for forensic analysis.
- We have also added the ability to perform cascade analysis. Any text or field can be selected for further analysis in a NEW Window, allowing the user to drill-down to the data they seek.

JSON Examiner
JSON is everywhere; now you can drill-down and perform analysis on JSON source files. The new JSON Examiner, accessible via the Tools menu, allows you to:
- View and format unstructured JSON files
- Search and filter content
- Expand and collapse nested structures
Perfect for analysing preference files, configuration settings, and client-side storage.

User Interface Improvements
This release also includes a range of UI enhancements to improve workflow and usability:
- The Filter menu has been considerably expanded and has quick access to common and predefined filters
- We have made numerous improvements to layout, panel management, and column resizing
- Updated icons and visual polish for an even more intuitive experience
Expanded Browser Support
NetAnalysis® v4.0 includes updated support for hundreds of browser versions across Chrome, Firefox, Edge, Safari, Opera, and more, including both desktop and mobile platforms. This ensures continued compatibility with the latest releases and artefact formats.
Summary
NetAnalysis® v4.0 is a major milestone in forensic browser analysis, delivering both powerful new functionality and workflow improvements that make your job easier, faster, and more accurate. As always, we look forward to hearing how these new features help your investigations. If you have any questions or suggestions, please get in touch with our support team.
NetAnalysis® Change Log
The full list of changes can be found here: NetAnalysis® v4.0 Change Log.
Release Notes for HstEx® Version 6.0
We are excited to announce the release of HstEx® v6.0, a significant update that redefines digital forensics data recovery. This release delivers powerful new capabilities, enhanced performance, and improved accuracy, enabling investigators to uncover critical evidence more effectively than ever before. HstEx® v6 is designed to address the evolving challenges of digital investigations, providing cutting-edge tools to stay ahead in the field.

Key New Features and Improvements
HstEx® v6 introduces several key features and enhancements:
- Advanced Private Browsing Data Recovery: HstEx® v6 now offers comprehensive support for the recovery of Mozilla-based Private Browsing and Private Cache entries. This breakthrough capability allows investigators to access previously hidden browser artifacts, providing crucial insights into user activity.
- Enhanced Microsoft Edge Support: Stay ahead of browser updates with improved support for changes in Microsoft Edge Navigation History. HstEx® v6 ensures accurate and complete recovery of browsing data from the latest versions of Microsoft Edge.
- Improved Autofill Verification: HstEx® v6 includes enhanced verification of Chromium-based Autofill entries, ensuring the reliability and accuracy of recovered data. This improvement helps investigators to confidently use Autofill data in their investigations.
- Detailed Physical Device Logging: HstEx® v6 now provides enhanced logging for physical devices, including manufacturer, serial number, and firmware version. This detailed information streamlines device identification and management, improving the efficiency of investigations.
- Enhanced SQLite Recovery: HstEx® v6 features an improved detection algorithm for recovering SQLite entries from unstructured data. This enhancement increases the success rate of data recovery from deleted, damaged or fragmented databases.
These updates collectively provide a more robust, efficient, and reliable experience for digital forensics professionals. HstEx® v6 empowers investigators with the tools they need to tackle the most complex cases and uncover critical browser evidence.
HstEx® Change Log
The full list of changes can be found here: HstEx® v6.0 Change Log.
Read More
- Browser Forensics with NetAnalysis® – the pinnacle of browser forensic extraction and analysis, delivering unrivalled precision and depth in digital investigations.
- Recovering Browser Artefacts with HstEx® – the ultimate solution for recovering web browser artefacts, seamlessly unlocking critical evidence across desktop and mobile platforms.