首页
社区
课程
招聘
[转帖]WinHex 17.2
2013-7-6 00:26 3359

[转帖]WinHex 17.2

2013-7-6 00:26
3359
WinHex 17.2 July 5, 2013
_http://www.winhex.net/
* Yet another acquisition option for users who need to or want to exclude certain data from forensic images. You can now create ordinary images, in raw format or as an .e01 evidence file - with all the known options such as hashing, compression, encryption, splitting - and exclude the data in clusters associated with files that you hide before starting the acquisition process. The resulting image is called a cleansed image. The affected sectors are zeroed out in the image and optionally marked with an easily recognizable "watermark" of your choice. All other data is copied to the image normally.

Useful for anyone who needs to redact certain files in the file system, but otherwise wants to create an ordinary forensically sound sector-wise image, compatible with other tools. A must in countries whose legislation specially protects the most private personal data of individuals and certain data acquired from custodians of professional secrets (e.g. lawyers and physicians, whose profession swears them to secrecy/confidentiality). For a comparison of evidence file containers, skeleton images and cleansed images, which all serve similar purposes, please see http://www.x-ways.net/investigator/containers_vs_skeleton_images.html.

Before you start the imaging process for a partitioned disk, open the partitions in which the files are located that you would like to exclude from the image. Wait till the volume snapshot has been taken if it was not taken before. Then hide the files. You do not need to open and take volume snapshots of partitions whose data you would like to include completely.

Note that alternatively you can retroactively cleanse (redact) already created complete raw images, in WinHex, by securely wiping files selected files via the directory browser context menu. The granularity of this operation is not limited to entire clusters. For example, that means it can also wipe files in NTFS file systems with so-called resident/inline storage and it does not erase file slack along.
* Totally revised indexing engine with many advantages: Created optionally at the same time when then volume snapshot is refined (synergy saves time), faster to create than before, no separate optimization step, just 1 index for multiple code pages/character sets, just 1 word list for multiple code pages/character sets (i.e. less duplicates), GREP searches in the index possible, multiple indexes with different names for different purposes may coexist for the same evidence object, indexing with regular expressions possible (details to be revealed later), more convenient search hit review (exactly like for ordinary search hits, search hits are stored permanently immediately, allowing for immediate logical AND and NEAR combinations), and more.

At the moment the old and the new indexing engines coexist within the program. To use the old indexing engine use the menu commands Search | Indexing (to create an index) and Search | Search in Index (to search in the index). To use the new indexing engine use the menu commands Specialist | Refine Volume Snapshot (to create an index) and Search | Simultaneous Search (to search in the index, select "Search in Index" in the drop-down box).
* Events recorded by Skype are now output to the event list (chats, calls, file transfers, account creation, ...). When sorting these events by their timestamps, you can read all chats messages in chronological order.
* Metadata extraction from PE .exe files with version resources.
* New directory browser column: Unique ID. Similar to the internal ID, but unique within the entire case, not just within the evidence object. A filter for this column will probably be added at a later time.
* The options "Group files and directory", "List dir.s when exploring recursively" and "Apply filters to directories, too" are now remembered separately by the normal directory browser, search hit lists and event lists.
* X-Tensions API: Ability to retrieve the result of the skin tone/gray scale analysis of pictures programmatically, via XWF_GetItemInformation.
* Several minor improvements.

http://www.x-ways.net/winhex.zip


[CTF入门培训]顶尖高校博士及硕士团队亲授《30小时教你玩转CTF》,视频+靶场+题目!助力进入CTF世界

收藏
点赞1
打赏
分享
最新回复 (20)
雪    币: 2956
活跃值: (66)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
bankw 2013-7-7 02:20
2
0
简体文件变成txt文件了?怎么弄啊。
雪    币: 8764
活跃值: (2583)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
obma 2013-7-7 14:48
3
0
在无忧论坛(现在成了达思的广告空间了)经常见你,又在此看到了。
把CHINESE.DAT改名为CHINESE.TXT,把CHINESE2.DAT改名为CHINESE.DAT就可以了。不过菜单小有变化(U码增加大头与小头区别+复制稀疏文件+语言加入波兰语和俄语,LANGUAGE在17.1的基础上增加34条新词条)
雪    币: 2956
活跃值: (66)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
bankw 2013-7-8 02:15
4
0
广告空间?没看明白。
要是谁弄个新的语言文件就好了。
雪    币: 406
活跃值: (164)
能力值: ( LV12,RANK:250 )
在线值:
发帖
回帖
粉丝
荒野无灯 5 2013-7-8 04:13
5
0
更新真快啊~~
雪    币: 8764
活跃值: (2583)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
obma 2013-7-8 09:50
6
0
无忧启动论坛 的 数据恢复区 最近全是达思科的广告啊!

                (改名)              (改名)
另,上面都说了,把原CHINSES.DAT--------->CHINSES.TXT,CHINSES2.DAT--------->CHINSES.DAT 就可以了。除了添加新词汇,没必要重新做吧。
雪    币: 14
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
InFour 2013-7-8 10:12
7
0
无忧倒是有人搞,后来好像帖子关了。
雪    币: 8764
活跃值: (2583)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
obma 2013-7-8 11:18
8
0
上一个译文在此,翻译不好,后面30多句新增词汇没有翻译,需要就下吧。

下载附件,解压到 Winhex17.2 目录(如有,需替换以前的同名文件)

winhex17_CN.7z
上传的附件:
雪    币: 239
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
amulin 2013-7-8 11:22
9
0
微笑又要来补一刀了
雪    币: 2956
活跃值: (66)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
bankw 2013-7-8 11:41
10
0
谢谢,用上了。
雪    币: 4902
活跃值: (90)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
奘和 2013-7-8 17:55
11
0
等微笑补刀。。。
雪    币: 14
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
InFour 2013-7-8 19:38
12
0
这个语言文件有的地方显示不正确
雪    币: 8764
活跃值: (2583)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
obma 2013-7-9 09:34
13
0
可能吧,两个文件都是 Winhex 17.1 的,这次升级可能有句式上的变动,因未与英语逐条比对,稍后有空详细检查一下。
雪    币: 83429
活跃值: (198485)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2013-7-14 08:33
14
0
WinHex 17.2 RePack
_http://rghost.ru/47405424
雪    币: 14
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
InFour 2013-7-17 22:49
15
0
不知道楼上为什么要重新打包
雪    币: 83429
活跃值: (198485)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2013-7-17 23:17
16
0
+1
雪    币: 201
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
lidar 2013-7-19 11:17
17
0
好久没更新了  下载来看看
雪    币: 1906
活跃值: (712)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
tigerwood 2013-8-8 11:13
18
0
多谢楼主分享,呵呵
雪    币: 14
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
InFour 2013-8-8 20:33
19
0
雪    币: 216
活跃值: (39)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
scriptkit 2013-8-13 10:08
20
0
嘿嘿多谢
雪    币: 83429
活跃值: (198485)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2013-8-13 13:34
21
0
X-Ways WinHex 17.2 SR-6
http://pan.baidu.com/share/link?shareid=471481026&uk=3912526821

游客
登录 | 注册 方可回帖
返回