Data Recovery from AFD, E01, and S01 Forensic Disk Images
In this article, we will examine AFD, E01, and S01 disk image formats, which are widely used in digital forensics, information security, and professional data recovery. We will explain the purpose of each format, where they are used in practice, and what data they can contain. We will also review the features, advantages, and limitations of each format.

- Security and integrity of digital evidence
- Forensic images: E01, AFD, and S01
- How to recover data from a forensic image
- Conclusion
- Frequently Asked Questions
- Comments
In digital forensics, disk images are used to create exact copies of storage devices while preserving the data structure, file system, and other critical information. Such images make it possible to examine the original medium without the risk of altering or damaging its contents. Among the formats that may be encountered during forensic analysis are AFD, E01, and S01.
However, even the presence of a ready-made forensic image does not guarantee that all files can be opened or copied immediately. Data may be deleted, fragmented, corrupted, or located in partitions and file systems that are not recognized by standard Windows tools. In such cases, specialized tools are required to analyze the image and search for lost data.
In this article, we will explain how to open AFD, E01, and S01 forensic images, analyze them, and restore access to deleted or lost files. We will also cover the specifics of working with such images and the procedure for recovering data without making changes to the original evidence file.
Forensic Data Recovery from AFD, E01, S01 Disk Images
Security and integrity of digital evidence
Forensic images may contain confidential and evidentiary information, so encryption is often used to protect them. This helps prevent unauthorized access and confirm data integrity. Such images are used in digital evidence analysis, deleted file recovery, and the examination of email and event logs.
Work with digital evidence is governed by international standards:
- One of the key standards is ISO/IEC 27037, which defines rules for the identification, collection, acquisition, and preservation of digital evidence. It requires creating an exact copy of the medium, protecting the data from any changes, and documenting all actions performed during evidence handling.
- In addition, the field of digital forensics widely uses ISO/IEC 17025, which establishes requirements for the competence of forensic laboratories and the quality of examinations.
Forensic images: E01, AFD, and S01
When creating a copy of a storage device, Exterro FTK Imager offers several image formats, among which AFD, E01, and S01 are most commonly used. These are forensic formats designed to create an exact bit-by-bit copy of a disk while preserving the file system, service data, and information about deleted files.
Such images allow you to capture the state of the storage device as accurately as possible at the time of acquisition and perform further analysis, digital examination, or data recovery without working with the original medium.
| Characteristic | AFD | E01 | S01 |
|---|---|---|---|
| Full name | Advanced Forensic Format | Expert Witness / EnCase Evidence Format | SMART / Expert Witness Image |
| File extensions | .afd | .e01, .e02, .e03, etc. | .s01, .s02, .s03, etc. |
| Type | Forensic disk image container | Forensic disk image container | Forensic disk image container |
| Primary purpose | Storage and analysis of forensic storage images | Creating and analyzing forensic disk copies | Creating and analyzing forensic images |
| Bit-by-bit copy of the medium | Yes | Yes, for bitstream images | Yes |
| Compression | Supported | Supported | Supported |
| Image segmentation | Possible depending on implementation | Yes, the image can consist of multiple segments | Yes |
| Metadata | May store service information about the image | Stores metadata and case information | Supports service information about the image |
| Integrity verification | Supported by format mechanisms | Checksums and hashing are used | Integrity control mechanisms are supported |
| Deleted file recovery | Possible if the corresponding data is present in the image | Possible, including analysis of unallocated space | Possible |
| File system handling | Depends on the analysis software | Depends on the analysis software | Depends on the analysis software |
| Popularity in forensic tools | A relatively common AFF format | Very widely supported | Supported by a number of specialized forensic applications |
| Typical use | Digital forensics, evidence examination | Forensic examination of disks and digital evidence | Forensic examination of disk images |
| Feature | An open format focused on forensic applications | One of the most widely used forensic image formats | A format associated with SMART/Expert Witness |
| Main advantage | Flexibility and focus on forensic analysis | Wide compatibility, compression, metadata, and integrity verification | Compression and preservation of the forensic image structure |
E01 format
The E01 format is one of the most widely used standards in digital forensics and forensic examinations. It creates an exact copy of the storage device and preserves service data for integrity verification: case number, examiner name, creation date, media description, and checksums. For this reason, E01 is widely used in digital forensics, cyber incident investigations, and digital evidence handling.
To create an image in E01 format, open Exterro FTK Imager. In the File menu, select Create Disk Image.

In the source selection window, choose Physical Drive, since we are creating a copy of a physical storage device.

Next, select the connected USB flash drive or other medium from which you want to create an image.

After that, the settings window will open.

Click Add and select E01 or Expert Witness Format from the format list. This option is used to create an image in E01 format.

At the next stage, fill in the service fields: case number, evidence number, device description, examiner name, and notes. This information will be stored inside the image and will help verify its origin during further analysis.

Then specify the folder where the file will be saved and set the image name.

If necessary, configure Image Fragment Size. If you need a single continuous file, set the value to 0. If the image needs to be split into parts, specify the fragment size in megabytes.

After configuring E01, do not start copying immediately if you need to create another image in a different format. Click Add again and proceed to create S01.
S01 format
S01 is designed for creating and storing digital evidence in the SMART software suite. It creates an exact copy of the storage device with service data for verifying information integrity. The format is used in digital examinations, incident investigations, corporate audits, and the storage of digital evidence. Although the S01 format is less common, it remains compatible with many digital forensics tools.
To add an image in S01 format, select Smart from the list of available formats. This option is used to create a Smart Disk Image in S01 format.

Next, fill in the information fields for the examined medium: case number, evidence number, device description, examiner name, and notes. Then specify the destination folder and set the file name.

After configuring S01, you can add another format. Now let us consider AFD, which differs from the previous formats in the way data is stored.
AFD format
AFD is a disk image format used in Exterro solutions for storing and analyzing digital evidence. Unlike E01 and S01, AFD stores data as a set of files in a separate folder, which is convenient for large volumes of information. The format supports compression, service metadata, and long-term storage of digital evidence: documents, emails, photos, videos, browser history, messages, databases, system logs, and deleted files.
To add an image in AFD format, in the image settings window click Add and select AFF or AFF Directory Image, depending on how this option is labeled in your version of the program.

After selecting the format, fill in the service information about the storage device: case number, evidence number, device description, examiner name, and notes. Then specify the destination folder.

After that, click Finish and start the image creation process. Wait for the copying and verification to complete.

After this, these images can be added to Hetman Partition Recovery for further analysis, viewing of found data, and file recovery to another physical storage device.
How to recover data from a forensic image
Mounting images
Mounting forensic images in Hetman Partition Recovery is very straightforward. The program supports AFD, E01, and S01 formats and displays such images as regular physical disks with partitions, a file system, and accessible files.

To attach a file, open the mounting menu in Hetman Partition Recovery and select the required type:
- For AFD, select AFF Directory Images and specify the folder containing its components.
- For E01, add the Expert Witness Format file.
- For S01, select Smart Disk Image and specify the directory where the corresponding files are stored.

Hetman Partition Recovery supports both compressed and uncompressed images of these formats, so no additional settings are required to mount them. After the image is added, the program will automatically display it in the list of storage devices as a separate disk. Make sure the required partitions and file system are available.

Recovering data from forensic images
Next, select the partition from which you need to recover data and start the analysis. Two scanning modes are available: Quick Scan and Full Scan:
- Use Quick Scan if the file system remains intact, the partition structure has not changed, and you need to find deleted files while preserving the original folder structure.
- Use Full Scan if the partition has been formatted, the file system is damaged, the partition structure has changed, or you need to find files by signatures. In this mode, the program performs a deep scan of the medium and searches for data by known file patterns.

After the analysis is complete, review the found files. Be sure to use the Preview feature to verify that the required documents, photos, videos, or other files open correctly.

If the required data is found, click Recover and save the files to another physical storage device.

Do not save recovered data back into the same image or to the disk from which recovery is being performed.
Conclusion
AFD, E01, and S01 forensic images make it possible to preserve exact copies of storage devices and examine them without needing to work directly with the original medium. However, if files have been deleted, the file system is damaged, or the partition structure is lost, simply mounting the image may not be sufficient to access the required information.
To recover data, it is important to correctly identify the image format, its structure, and its condition, and then analyze the available partitions, file systems, and unallocated space. Specialized data recovery software can find both existing files and deleted data, provided that its contents have not yet been overwritten.
When working with digital evidence, it is especially important not to modify the original forensic image. It is recommended to work with a copy and save the recovery results to another physical storage device. This approach reduces the risk of information loss and preserves the original image for further analysis.
Therefore, data recovery from AFD, E01, and S01 is possible even in complex cases, provided the image is not critically damaged and the required data still physically exists within it. The correct choice of tools and a systematic forensic image analysis process make it possible to effectively restore access to lost, deleted, or hidden files.







