AD Lab

Large-Scale Investigation and Processing


Why You Want It

Divide and conquer with AD Lab. This proven tool helps you power through massive data sets, handle various data types and run multiple cases at the same time, all within a collaborative, scalable environment. AD Lab uniquely enables distributed processing, allowing investigators to utilize additional hardware to dramatically increase their case processing and resolution speed.

While a single-person lab can radically speed up their processing using the four-worker distributed processing engines (DPEs) available with FTK®, labs handling massive data sets, utilizing a distributed workforce, or looking to collaborate with attorneys, HR or other parties, can step up to AD Lab.

As a centralized investigative platform, AD Lab adds powerful web-based review functionality and expanded DPE capabilities (up to 16 with the 6.2 release) with a centralized processing farm and centralized database infrastructure. With AD Lab, you get the fastest processing available on the market with virtually limitless scalability (depending on your own hardware). And AD Lab’s state-of-the-art data visualization drives you to deeper analysis by uncovering relationships and patterns that make better decisions possible.


Slow processing just doesn’t cut it, especially when case urgencies require virtually instantaneous data analysis. With the latest release, AccessData establishes the standard of excellence for high-speed, forensic processing. With AD Lab, massive datasets can now be processed four times faster than the previous version.


Your case volumes and investigative data sizes are staggering. AD Lab will scale up, and up! Throw more RAM at it and the scalability is virtually limitless.


The centralized database architecture and one shared case database keeps all parties on the same page and allows you to work through your cases at a record pace. With the web-based review system, non-technical users (attorneys, HR personnel, outside experts) can participate in the process without delay, regardless of their location.

Take Your Forensic Investigation to the Cloud!

AD Lab is now the first product in its category to be available to users in a cloud-based environment.

Scale your environment and control costs, paying only for what you use, when you need it with new AD Lab® in the cloud.

  • Save on hardware by installing Lab in a cloud environment and Bring Your Own License (BYOL).
  • Pay only for what you need, with the ability to scale computing and storage.
  • Purchase computing based on what you need in an operating budget instead of a capital budget.

AD Lab is now available on Amazon Web Services and can be obtained on the AWS Marketplace. You’ll be asked for your Lab license to gain access. Watch for the release on Microsoft Azure very soon!

Ready to prepare and deploy your AD Lab Environment in the cloud? Download the Steps here.

Large-Scale Investigation and Processing

When you need to quickly process huge datasets, handle various data types and run multiple cases at the same time, AD Lab helps conquer your caseload, all within a collaborative, scalable environment.

Features Built Around You

Capabilities to Empower You

  • Parse even more registry and Windows events in an easy to read, interactive and reportable Windows System Information tab. Also label, bookmark and export individual objects per category, allowing for easy searching, filtering and reporting.
  • Supports decryption of File Vault 2 from the APFS file system.
  • QView™ integration introduces a simple, intuitive and customizable review interface. Utilize multi-case functionality such as tagging, searching, labeling and bookmarking across multiple cases. Enjoy easy mobile chat application and multimedia review, along with similar face and image detection all backed by a unified database. And, a panels-driven interface means that you can customize the view to your liking.
  • Export your data into a portable case for offline review and sync back labels, bookmarks, comments and notes to the original case. Reviewers will also appreciate the ability to view the data in a near-native format.
  • Similar face and object detection allow investigators to quickly locate all images of a person or object across the case without having to train the system, which can use up valuable time and resources. Also, upload an image from outside the case and compare it to pictures within the current case without ingesting it.
  • Get a head start on your investigation with URL detection and parsing capabilities across devices without regard to browser, neatly organized under one section to easily review the data and connect the dots in your investigation.
  • FTK will ingest and support updated versions of LX01 and E01 images.
  • Automatically import and expand a nested forensic image with image within an image support.
  • Import and parse AFF4 images created from Mac® computers (generated by third-party solutions like MacQuisition by BlackBag).
  • Parse XFS file systems when investigating and collecting from RHEL Linux environments.
  • Leverage the power of your forensic environment with optimized support for unified database for the AWS/Amazon RDS configuration. Host your FTK database in AWS to upload, process and review for unmatched speed and scalability.
  • Cut down on OCR time by up to 30% with our efficient OCR engine.
  • Locate, manage, and filter mobile data more easily with a dedicated mobile tab. Use the message application filter to quickly isolate data from message applications like WhatsApp or Facebook.
  • View all associated EXIF data, including location, make and model of the device used to capture the images or video.
  • Collect, process and analyze datasets containing Apple file systems that are encrypted, compressed or deleted.
  • Decrypt a computer drive encrypted by the latest version of McAfee Drive Encryption and new L01 export support which eases the workflow of users when data must be used within multiple tools.
  • Scale your environment and pay only for what you use with reliable cloud processing and storage for AD Lab, available in Amazon Web Services™.
  • Web-based UI allows easy collaboration with your wide range of teams.
  • Granular user controls gives access to the data relevant to each person’s part of the investigation. Dividing the evidence creates a more efficient and secure workflow.
  • See all active jobs and easily change job processing order based on changing priorities without affecting progress.
  • Perform multipass data review and change indexing options without reprocessing your data.
  • Third party integrations provide the ability to share more hash data with Project VIC integration; and iSubmit® users will benefit from new integration.
  • Automate email notifications at more case milestones for more users; automatically expand audit log and evidence tracking detail to improve chain of custody documentation.
  • Multi-machine, forensic analysis with wizard-driven processing, filtering and reporting.
  • Analytics that allow you to see relationships and patterns that will help make decisions faster with state-of-the-art data visualization.
  • Configure and change the weighting criteria for sort after a search to reveal the most relevant results. Customizable processing profile buttons help create a set of standards for processing particular types of investigations.

What Clients Are Saying


  • Jump over to Resources for additional product brochures, case studies, white papers, as well as on-demand videos and more.RESOURCES
  • View our library of on-demand video tutorials.VIEW TUTORIALS



Deeper Insights for Investigations & Legal Review

Forensic Toolkit (FTK)®

Dead-Box Forensics

AD Enterprise

Live Data, Remote Collection & Cyber Forensics

AD eDiscovery®

Corporate Collection & ECA


Our Professional Services team can work with any size organization to provide scalable support for short- or long-term initiatives, based on your needs.

Contact us today to learn more about our products and our
approach to improving how you collect, analyze and use data.
Tell Me More