Icon Menu
Icon Search


What is F-Response?
F-Response is an easy to use, vendor neutral, patented software tool that enables “Live” forensics and eDiscovery over IP networks using the examiner’s tools of choice. Physical memory, disks, and volumes of the machines under inspection appear on the examiner’s machine as locally attached, read-only devices.

F-Response provides read-only access to full physical disks, logical disks, Cloud-based data, Databases and physical memory (RAM) over the network.

F-Response significantly increases the efficiency and affordability of digital forensics, incident response, data recovery, and eDiscovery efforts by presenting a means to manage the collection, preservation, and analysis process over any TCP/IP network, including the Internet.

F Response Quick Overview Video

F Response Universal Overview Video

Is F-Response Court Approved

There is no such thing as court-approved software. Courts approve experts and their methods, and courts admit evidence. Evidence collected with F-Response® has been and continues to be used successfully in courts across the country and around the world. Because F- Response® works. Accurately. Securely. Verifiably.

How F-Response works:
F-Response creates an authenticated, read-only connection between the examiner’s computer and the computer under inspection, over the network.

Why Use F-Response?
F-Response is inexpensive, flexible, vendor neutral, and does not require extensive training. Practitioners can learn to use it in a fraction of a day, and then fully leverage their existing arsenal of tools and training. Other network ready solutions are expensive, require considerable training to use, and force you to use the proprietary integrated vendor analysis tool.

F-Response term licenses are sold on an annual basis with no limitation on the number of installations or uses.

F-Response Highlights:
Forensically Sound & Secure: The examiner cannot alter Metadata, files, or make any change to the machine under inspection because all write operations are silently ignored by F-Response.

Supported Platforms: Provides network accessible, authenticated, RAW, read-only drive access to most computers.

  • Versatile: F-Response was designed to be completely vendor neutral. If your analysis software reads a hard drive, it will work with F-Response.

  • Highly Efficient: F-Response maintains a small active memory (RAM) Footprint and will not bog down the user’s workstation or entity’s network.

  • Scriptable: A language-neutral fully scriptable JSON Web Service is available, allowing a technical user of F-Response to script actions typically initiated manually in the Management Console.

  • Affordable: Fixed yearly license sold in 1 and 3 year increments. No seat limits. No add-ons. No surprises.

    What is F-Response Universal?
    F-Response Universal is a server-based product provided by F-Response leveraging patented technology ("F-Switch") to provide access to remote systems virtually anywhere in your network. F-Response Universal provides near instant access to Windows, Linux, and Apple OSX devices virtually regardless of the location provided they have network access.

    How does F-Response Universal work?
    F-Response Universal uses a patented remote connectivity technology that enables an authenticated, read-only connection to be created between the examiner's computer and the computer(s) under inspection, over any network. F-Response Universal readily traverses most firewalls, NAT/PAT routers, and other complex networking technologies making it remarkably fast and easy to connect to remote systems almost anywhere in the world.

    F-Response Universal is sold in 1 and 3 year license durations.

    What are the advantages of F-Response Universal over F-Response Enterprise?
    F-Response Universal provides access to remote Windows, Linux, and Apple OSX devices via the network, much like F-Response Enterprise. However, F-Response Universal does not require dongle(s), integrates more deeply in your environment, supports Active Directory authentication, and provides the full deployment console to all authenticated examiners. In addition, F-Response Universal often does not require firewall modifications and is completely encrypted by default. For additional differences between F-Response Universal and the entire F-Response product suite see the Product Matrix.

    Who would use F-Response Universal?
    For E-Discovery Professionals
    F-Response Universal was designed to give litigation teams extended geographic and technical reach to access unlimited live remote machines data in a completely write-protected manner.

    Once connected, the files and folders on remote devices are presented via a DiscoveryShare(TM), giving litigation teams the ability to review data by simply using the Windows file browser for quick review, or their litigation tools for more extensive research.

    For Forensic Investigators
    F-Response Universal includes access to remote physical disks, volumes, partitions, and RAID devices, allowing a Forensic examiner to leverage existing tools, techniques, and methodologies to perform investigations with pinpoint accuracy and precision.

    For Incident Handlers/Responders
    F-Response Universal presents remote Windows computer physical memory via the MemoryShare(TM) as a live image file, giving the handler the ability to simply collect the image file or analyze it using a popular forensics tool such as Volatility. The image file is not a snapshot of the remote physical memory, rather it represents the live physical memory of the remote machine.

    Buy F-Response Universal
    F-Response Universal is available in 1 and 3 year license terms .