首页
社区
课程
招聘
[ZT]WinHex 13.9 Mar 23, 2007
发表于: 2007-3-24 12:17 2400

[ZT]WinHex 13.9 Mar 23, 2007

2007-3-24 12:17
2400

What's new?

* Forensic licenses only: Ability to open remote network drives at a logical level, if a drive letter has been assigned locally. The directory browser, File mode, Preview mode, Gallery mode, and Calendar mode are all available. A volume snapshot can be taken and refined (not with the options that require sector access), filters can be used, keyword searches can be run. On the other hand, sectors, free space, slack space, deleted files, alternate data streams, owner SIDs etc. cannot be displayed. Very useful to preview remote network drives on site and e.g. search/copy relevant documents if no physical access to certain computers on a network is available. Another benefit is that NTFS-encrypted files (EFS) to which the currently logged-on user has access can be opened and processed as if they were not encrypted.

* Forensic licenses only: Ability to open local drive letters without administrator rights. The same limitations apply.

* Support for the Ext4 file system (specialist and forensic licenses only).

* X-Ways Forensics now warns when opening a case if that case has already been opened by someone else (if not in read-only mode).

* When decoding the text in PDF, HTML, RTF, StarOffice, WordPerfect, etc. files for logical searches and indexing, the result is now optionally buffered (can be disabled in Options | Viewer Programs). As the decoding is relatively slow, the benefits of the buffer are that further searches will run noticebably faster if there are many such files and that there can now be context previews even for search hits in the decoded version of files! This renders examining search hit lists much more convenient. Decoded text output is now either ASCII or Unicode on a per-file basis, depending on the nature of the characters in the text.

* The Print command in the directory browser context menu is now more flexible in that it allows to print files with the help of the viewer component either with or without its own cover page. As a new third option it is now possible now have X-Ways Forensics print the filename and path itself, on the first page. This option is not bound by the same path length limitations as the header printed by the viewer component. To avoid that the path is printed twice on the first page, have either X-Ways Forensics or the viewer component print it, not both.

* It's easier now to identify the evidence object in the Case Data window that is represented by the active data window, as all the other evidence objects, including their directory trees, are displayed in gray.

* Changes among physical disks (e.g. newly attached external USB hard disks) are now detected without having to restart the program.

* File containers now optionally have an internal designation (the XWFS volume label). Useful as another means to identify to which case/suspect a container belongs since the filename might be too generic (used similarly in different cases) or could be accidentally changed.

* A new switch "+19" in investigator.ini allows to keep users of X-Ways Investigator from opening images/containers that are not located in the default path for images/containers. Useful if the default path is externally controlled and users must not inadvertently add images from unrelated cases.

* Several other minor improvements.


http://www.x-ways.net/winhex.zip

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 1
支持
分享
最新回复 (1)
雪    币: 201
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
老大   翻译了没?
2007-3-25 12:25
0
游客
登录 | 注册 方可回帖
返回
//