Helix Data Forensics/System Repair iso
Helix is a very hard to find bootable Knoppix based iso, which is useful for Data Forensics. Some of the uses for this CD are:
Finding multiple data streams in NTFS file systems. Searching an entire disk partition for a string of text. viewing all the text on a disk partition viewing the raw hex of a disk partition constructing a time line, based on creation date and last access date for all files running FSCK on your root file system using the DoD spec version of the DD command, dcfldd, which has a progress output calculating an md5sum for a disk partition copying a disk partition or entire disk to another disk, or file. analyzing the bit stream copies of disks, which are in file format analyzing the behavior of running programs breaking into a windows system for forensic purposes reading and analyzing outlook email for forensic purposes reading and analyzing the contents of windows index.dat files, and cookies, temporary Internet files, and history of Internet explorer opening disk partitions for read/write(you can edit fstab) will autorun on a booted windows system contains autopsy and sleuthkit lde editable /etc directory boots into root auto configures every disk partition it finds in fstab has web browser will boot into KDE or gnome on certain systems uses a decent screen resolution This bootable CD is a basic debian based Knoppix knockoff, which is customized for system repair and data forensics. I carry it wherever I go. Frame buffer mode work on lcd monitors. The features on this disk are endless, and there is full list of man pages on the CD. http://www.efense.com/helix |
So what uses have YOU found for it?
|
Nevermind, answered my own question.
|
All times are GMT -5. The time now is 12:53 AM. |