Professional Documents
Culture Documents
HELIX IS TARGETED TOWARDS THE MORE EXPERIENCED USERS AND FORENSIC INVESTIGATORS(DONT BE AFRAID !!!!U ALREADY ARE EXPERIENCED ENOUGH)
THE LATEST VERSION OF HELIX, HELIX 3, IS BASED ON THE UBUNTU VERSION OF LINUX
DUE TO HELIX BEING A LIVE DISC IT IS POSSIBLE TO RUN IT ON A "SUSPECT" MACHINE WHILST THE INSTALLED OPERATING SYSTEM REMAINS INACTIVE
LIVE NETWORK FORENSICS ARE POSSIBLE WHEN RUNNING THE HELIX LIVE DISC ALLOWING FOR USERS TO PERFORM CHECKS ON NETWORKS THAT THEIR MACHINES ARE ATTACHED TO
WIRESHARK
VIRUS SCANNER
GTKHASH
TRUE CRYPT
ROOT TERMINAL
LINEN
ADEPTO
IMAGING PROGRAM OPEN SOURCE GRAPHICAL INTERFACE TO THE CMD LINE TOOLS FOR THE ANALYSIS OF NTFS, FAT, EXT2FS BLESS IS A HIGH QUALITY, FULL FEATURED HEX EDITOR UTILITY FOR COMPUTING MESSAGE DIGESTS OR CHECKSUMS SP HASH INCL MD 5/6, SHA1/256, SHA512, TIGER & WHIRLPOOL
AUTOPSY
BLESS HEX EDITOR GTKHASH HFS VOLUME BROWSER
HFS IS THE HIERARCHICAL FILE SYSTEM, THE NATIVE VOLUME FORMAT USED ON MODERN MACINTOSH COMPUTERS.
IMAGING PROGRAM
OPHCRACK REGISTRY VIEWER RETRIEVER ROOT TERMINAL TRUE CRYPT VIRUS SCANNER WIRESHARK XFPROT
OPHCRACK IS A WINDOWS PASSWORD CRACKER BASED ON RAINBOW TABLES NTLM,SAM FILES ANALYSER
Tools that are used to acquire drives and images and files
Tools that are used to analyze those images drives and files with.
ADEPTO FALLS INTO THE FIRST CATEGORY, THE ACQUISITION TYPE OF TOOL BECAUSE IT REALLY DOESN'T ANALYZE ANYTHING, IT JUST GRABS A FORENSICALLY SOUND COPY OR IMAGE OF A HARD DISK
GUI drive imaging program for the DD and the DCFL-DD Command Line Imaging
Creates forensically sound images of hard disks and other media, CD's, USB Sticks and so forth.