You are on page 1of 16

HELIX SOFTWARE HAS NO NECESSITY OF USING CMD LINE TOOLS .

ITS ALL GUI

HELIX IS A LIVE LINUX CD DESIGNED FOR LIVE INCIDENT RESPONSE

HELIX IS TARGETED TOWARDS THE MORE EXPERIENCED USERS AND FORENSIC INVESTIGATORS(DONT BE AFRAID !!!!U ALREADY ARE EXPERIENCED ENOUGH)

THE LATEST VERSION OF HELIX, HELIX 3, IS BASED ON THE UBUNTU VERSION OF LINUX

DUE TO HELIX BEING A LIVE DISC IT IS POSSIBLE TO RUN IT ON A "SUSPECT" MACHINE WHILST THE INSTALLED OPERATING SYSTEM REMAINS INACTIVE

LIVE NETWORK FORENSICS ARE POSSIBLE WHEN RUNNING THE HELIX LIVE DISC ALLOWING FOR USERS TO PERFORM CHECKS ON NETWORKS THAT THEIR MACHINES ARE ATTACHED TO

For NON LINUX familiar users.

ADEPTO XFPROT AUTOPSY

WIRESHARK

BLESS HEX EDITOR

VIRUS SCANNER

GTKHASH

TRUE CRYPT

HFS VOLUME BROWSER

ROOT TERMINAL

LINEN

RETRIEVER REGISTRY VIWER OPHCRACK

MELD DIFF VIEWER

ADEPTO

IMAGING PROGRAM OPEN SOURCE GRAPHICAL INTERFACE TO THE CMD LINE TOOLS FOR THE ANALYSIS OF NTFS, FAT, EXT2FS BLESS IS A HIGH QUALITY, FULL FEATURED HEX EDITOR UTILITY FOR COMPUTING MESSAGE DIGESTS OR CHECKSUMS SP HASH INCL MD 5/6, SHA1/256, SHA512, TIGER & WHIRLPOOL

AUTOPSY
BLESS HEX EDITOR GTKHASH HFS VOLUME BROWSER

HFS IS THE HIERARCHICAL FILE SYSTEM, THE NATIVE VOLUME FORMAT USED ON MODERN MACINTOSH COMPUTERS.
IMAGING PROGRAM

LINEN MELD DIFF VIEWER

COMPARISON BETWEEN FILES AND DIRECTORIES

OPHCRACK REGISTRY VIEWER RETRIEVER ROOT TERMINAL TRUE CRYPT VIRUS SCANNER WIRESHARK XFPROT

OPHCRACK IS A WINDOWS PASSWORD CRACKER BASED ON RAINBOW TABLES NTLM,SAM FILES ANALYSER

FINDS CERTAIN KINDS OF FILES AND GATHERS THEM TOGETHER


TAKES YOU TO THE ROOT TERMINAL U KNOW THIS ENOUGH CLAMTK VIRUS SCANNER AV FOR LINUX NETWORK PROTOCOL ANALYZER FOR UNIX AND WINDOWS XFPROT is a graphical frontend for the F-Prot Antivirus

MOUSE @ LAPTOPS,VIRTUAL MACHINES

IF INSTALLED ON HDDTHEN FEW TOOLS DONT FUNCTION.

RESOLUTION IN VIRTUAL BOX

Most tools fall under one or two broad categories

Tools that are used to acquire drives and images and files

Tools that are used to analyze those images drives and files with.

ADEPTO FALLS INTO THE FIRST CATEGORY, THE ACQUISITION TYPE OF TOOL BECAUSE IT REALLY DOESN'T ANALYZE ANYTHING, IT JUST GRABS A FORENSICALLY SOUND COPY OR IMAGE OF A HARD DISK

One of the first computer forensic tools

Imaging program that's found on the Helix Live Cd

GUI drive imaging program for the DD and the DCFL-DD Command Line Imaging

Creates forensically sound images of hard disks and other media, CD's, USB Sticks and so forth.

You might also like