15 сентября 2008 года вышла новая версия HELIX
Helix 2008R1 (2.0) (September 15, 2008)
MD5 hash value of the iso is 93a285bfa8ab93d664d508e5b12446d3
Linux (Bootable) Side:
• [UPD] Helix no longer based on Knoppix
• [UPD] Guidance Software Linen v6.11.2.2
• [UPD] afflib v3.3.3 - Open and extensible file format designed to store disk images and associated metadata
• [UPD] aimage v3.1.0 - Advanced disk imager
• [UPD] autopsy v2.08-2 - GUI frontend to sleuthkit tools
• [UPD] sleuthkit v2.52-1 - Open source digital investigation forensic tools
• [UPD] chkrootkit v0.47-1 - Determine whether system is infected with a rootkit
• [UPD] chntpw v0.99.3-1 - Utility to overwrite Windows SAM passwords
• [UPD] clamav v0.92.1 - GPL antivirus scanner
• [UPD] foremost v1.5.4-1 - Data carving based on headers, footers, and internal data structure
• [UPD] lvm2 v2.02.26 - Userspace toolset to provide logical volume management
• [UPD] md5deep v3.1 - Compute MD5, SHA-1, SHA-256, Tiger, Whirlpool message digests
• [UPD] readpst v0.5.2.1 - Convert pst files to mbox format
• [UPD] sg3-utils v1.24-1 - utility for working with generic scsi devices
• [UPD] ssdeep v2.0 -Fuzzy hashing to compare similar but not idetical files
• [UPD] tcpreplay v3.2.3-1 - Replay network traffic stored in pcap files
• [UPD] tcpxtract v1.0.1-1 - Extract files from captured pcap files
• [UPD] vinetto v0.6.0 - Examine Thumbs .db files
• [UPD] Wireshark v1.0.2-1 - Network protocol analyzer
• [UPD] dd_rescue v1.13.3 - Very good dd variant to recover crashed partitions.
• [ADD] winlockpwn v1.0 - Bypasses windows authentication via firewire
• [ADD] bioskbsnarf v1.0 - Python code to parse and print bios-real-mode-keyboard-interrupt-buffer
• [ADD] dc3dd v6.9.91 - Patched version of GNU dd with added forensic features
• [ADD] Volatility v1.3 - Open framework for the extraction of artifacts from RAM dumps
• [ADD] tableau-parm v0.1.0.2 - Command line tool to interact with Tableau forensic write blockers
• [ADD] gtkhash v0.2.0.1 - GTK+ utility for computing message digests
• [ADD] bless v0.6.0 - Hex editor with read/write support for block devices
• [ADD] clamtk v3.08-1 - Graphical front end to clamav
• [ADD] meld v1.1.5.1 - Diff and merge utility
• [ADD] ophcrack v2.4.1 - Windows password cracker based on rainbow tables (not included)
• [ADD] samdump2 v1.1.1 - Dump Windows SAM file for cracking
• [RMV] PyFlag - removed for space and performace reasons
Windows (Live) Side:
• [UPD] Windows Forensic Toolchest(TM) (WFT) v3.0.03
• [UPD] AccessData® FTK® Imager v2.5.3.14
• [UPD] Nirsoft Access Password Recovery v1.1.2.0
• [UPD] Nirsoft Lists USB Devices v1.2.0.0
• [UPD] Nirsoft Remote Desktop Password Recovery v1.0.1.0
• [UPD] Nirsoft Outlook PST Password Recovery v1.1.0.0
• [UPD] Nirsoft Protected Storage PassView v1.6.3.0
• [UPD] Nirsoft Network Password Recovery v1.1.2.0
• [UPD] Nirsoft MozillaCookiesView v1.1.2.0
• [UPD] Nirsoft Instant Messengers Password Recovery v1.2.0.139
• [UPD] Nirsoft Mail Password Recovery v1.4.3.149
• [UPD] Nirsoft LSA Secrets View v1.0.0.0
• [UPD] Nirsoft IE History View v1.3.7.0
• [UPD] Nirsoft IE Cookies View v1.7.1.102
• [UPD] Nirsoft IE Cache View v1.1.2.0
• [UPD] IRCR to fix paths
• [ADD] Nirsoft WirelessKeyView v1.1.6.0
• [ADD] Nirsoft List of all network resources v1.1.1.0
• [ADD] Nirsoft Mozilla History View v1.0.4.0
• [ADD] Nirsoft Mozilla Cache View v1.0.8.0
• [ADD] Nirsoft IPNetInfo v1.1.1.0
• [ADD] Nirsoft list DLLs that are automatically injected on every process v1.0.0.0
• [ADD] Nirsoft Internet Explorer Passwords Viewer v1.0.8.0
• [ADD] Guidance Winen RAM imager v6.11.2.2
• [ADD] Mantech MDD RAM imager v1.3
• [ADD] Mathieu Suiche Win32dd RAM imager v1.1.20080818
Также, теперь у программы новый сайт
http://helix.e-fense.com/.
Форум поддержки
http://forums.e-fense.com/ .
Руководство пользователя на английском :
http://helix.e-fense.com/Docs/Helix0307.pdf
К сожалению в настоящее время обновленный HELIX можно приобрести только за деньги: 20$ за диск + 10$ на почтовые расходы.
Авторы программы обещают в ближайшее время разместить программу на серверах и предоставить к ней доступ всем желающим. Ждем-с.
А пока несколько скриншотов сего чуда:
