Nesta versão, o Linux utilizado como base foi o Ubuntu, o que certamente facilitará no processo de atualização das várias ferramentas que compõem a distribuição - listadas abaixo:
Ferramentas Gráficas:
- Adepto & Air - GUI front-ends to dd/dcfldd/sdd
- linen: EnCase Image Acquisition Tool
- Retriever: (picture/video) capturing utility for “quick peeks”, and general searches
- Autopsy Forensic Browser - graphical interface to the command line digital investigation analysis tools in The Sleuth Kit
- pyFlag - simplify the process of log file analysis and forensic investigations
- RegViewer - *Nix viewer / navigator for windows registry file
- xhfs - graphical front-end for browsing and copying files on HFS-formatted
volumes - Ethereal - allow you to interactively browse network traffic
- ClamAV and F-Prot Anti Virus Scanners
- 2hash: MD5 & SHA1 parallel hashing.
- bmap: Detect & Recover data in used slackspace
- ChaosReader: Trace tcpdump files and extract data
- chkrootkit: Look for rootkits.
- chntpw: Change Windows passwords.
- dcfldd: dd replacement from the DCFL.
- e2recover: Recover deleted files in ext2 file systems.
- f-prot: F-Prot Anti Virus Scanner.
- fatback: Analyze and recover deleted FAT files.
- faust.pl: Analyze elf binaries and bash scripts.
- fenris: debugging, tracing, decompiling.
- foremost: Carve files based on header and footer.
- ftimes: A toolset for forensic data acquisition.
- galleta: Cookie analyzer for Internet Explorer.
- glimpse: Indexing and query system.
- grepmail: Grep through mailboxes.
- logfinder.py: EFF logfinder utility.
- logsh: Log your terminal session
- lshw: Hardware Lister.
- mac-robber: TCT's graverobber written in C.
- md5deep: Recursive md5sum with db lookups.
- outguess : Steganography detection suite.
- pasco: Forensic tool for Internet Explorer Analysis.
- rifiuti: "Recycle BIN" analyzer.
- rkhunter: Rootkit hunter.
- scalpel: Fast File Carver
- sdd: Specialized dd w/better performance.
- sha1deep: Recursive sha1sum with db lookups.
- sha256eep: Recursive sha1sum with db lookups.
- stegdetect: Steganography detection suite.
- wipe: Secure file deletion.
Várias organizações utilizam o Helix como base para treinamentos :
Bom dia Sandro!
ReplyDeleteEstou tentando instalar o Helix3 no HD e não passo ta tela de particionamento. Na verdade nem chega nesta tela, travando antes.
Você tem alguma dica?
Pierre, infelizmente o installer do Helix3 é bugado, e você precisa particionar manualmente o HD antes de instalá-lo, ok?
ReplyDeleteDepois disto, tudo deve funcionar como esperado.
Referencia: http://www.shortinfosec.net/2008/11/new-helix3-forensic-cd-welcome.html
como faco pra recuperar o historico da web do gwmail.com q foi excluido hontem
ReplyDelete