Back to Downloads

AtlantImage

v1.0.0WindowsFree

Most forensic acquisition still means juggling five separate tools, each with its own license, install, and quirks. AtlantImage replaces them with a single portable executable that images drives, verifies evidence, triages live systems, recovers deleted files, and decrypts BitLocker offline. Every acquisition is hashed with MD5, SHA-1, and SHA-256, written with a manifest and audit log, and can be re-verified byte for byte. Written in Rust, built from published specifications, and cross-validated against the reference tools.

Download Free (2.8 MB)Windows - 64-bit architecture - No account needed
AtlantImage screenshot 1
AtlantImage screenshot 2
AtlantImage screenshot 3

Download AtlantImage

2.8 MB - Windows - Free - No account required

Download Now

System Requirements

  • Windows 10 or Windows 11
  • 64-bit architecture
  • Administrator privileges for device, volume, triage, undelete, and BitLocker operations (auto-elevates)
  • No install and no runtime required (self-contained)

Release Notes

v1.0.02026-06-25
  • Forensic disk imaging to raw (dd) and EnCase E01 with on-the-fly hashing and read-back verification
  • Bad-sector recovery and Volume Shadow Copy acquisition
  • Live NTFS triage of $MFT, $LogFile, and $UsnJrnl:$J
  • NTFS file undelete with TRIM-aware integrity labeling
  • BitLocker offline decryption from recovery password
  • Desktop app plus scriptable command line