首页
社区
课程
招聘
[转帖]WinHex 14.8
2008-2-27 12:41 6856

[转帖]WinHex 14.8

2008-2-27 12:41
6856
WinHex 14.8

A preview version of X-Ways Forensics 14.8 is now available. The download link can be retrieved by querying one's license status.

What's new?

* Ability to extract JPEG pictures from video files, in a user-defined interval (e.g. every 20 seconds). Immensely useful if you have to systematically check many videos for inappropriate or illegal content (e.g. child pornography). Looking at extracted pictures in the gallery is much faster and more comfortable than having to watch each video entirely one after the other, as the amount of data is vastly reduced, and the extraction process can be run unattended e.g. over night.

Also useful if you need to include still pictures in a printed report. The extracted pictures of each video are collected in a virtual directory named after the orginal video file, as virtual files, in the same path as the original file, so that it's easy to link suspicious still pictures back to a video. The first extracted picture of a video at the same time serves as a preview picture for the video file in Preview and Gallery mode. ASF/WMV videos protected with digital rights management (DRM) cannot be processed and are consequentially marked with e! in the Attr. column.

Requires an external program, either the non-GUI version of MPlayer and its separately downloadable codec package (extract to "codecs" subdirectory of MPlayer), or Forensic Framer (available February 2008). The program has to be selected in Options | Viewer Programs. Pictures can be extracted from these video formats and codecs.

* Ability to rename virtual directories, with a new command in the directory browser context menu.

* Ability to preview/view $EFS logged utility streams (LUS).

* The option to filter out $EFS logged utility streams was removed from the directory browser option dialog. An option was added that keeps NTFS LUS from being included in newly taken volume snapshots in the first place, or only non-$EFS LUS. Useful for NTFS volumes written by Windows Vista if you are not interested in NTFS LUS.

* Attribute filters for NTFS $EFS, other logged utility streams, NTFS offline files, files with object ID, Unix/Linux symlinks, and other Unix/Linux special files.

* Attribute filters for pictures that were extracted from videos and for virtual files that were manually attached to a volume snapshot.

* Option to retain alternate data streams as ADS when using the Recover/Copy command if the output volume is formatted with NTFS. (forensic license only) If disabled or if copied to a different file system, ADS are recreated as conventional files, as before.

* When using the Recover/Copy command to copy files including their path, the name of the evidence object is now recreated as a directory also if "Default to evidence object folders for output" is unchecked in the case properties, not only when copying from a recursively explored case root window.

* Metadata extraction from MP3 files. ID3-embedded files other than JPEG and PNG (which can be automatically extracted) are indicated by a special report table once discovered.

* File Type Signatures.txt, File Type Categories.txt, and file carving further expanded and improved.

* Support for anchors in the GREP syntax: \b for a word boundary, ^ for the start of a file, $ for the end of a file.

* Further improved partial support for CD-ROM XA.

* Should X-Ways Forensics crash during Refine Volume Snapshot, Logical Search or Indexing whenever it is dealing with one of the file in the volume snapshot, you will automatically be pointed to the offending file when you restart the program, so that you can easily omit it when trying again. Depends on a new option in Security Options. The VS.log file known from v14.7 is no longer created.


http://www.x-ways.net/winhex.zip

[培训]二进制漏洞攻防(第3期);满10人开班;模糊测试与工具使用二次开发;网络协议漏洞挖掘;Linux内核漏洞挖掘与利用;AOSP漏洞挖掘与利用;代码审计。

收藏
点赞1
打赏
分享
最新回复 (13)
雪    币: 5918
活跃值: (202)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
WangXiong 2008-2-27 16:31
2
0
好东西,谢谢
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
qijiashe 2008-2-27 17:11
3
0
这东西不知道为什么突然不支持中文了,一直在用WinHex 13.0 SR-12
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
lj刘军 2008-2-27 20:25
4
0
楼上,不支持中文吗
雪    币: 1505
能力值: (RANK:210 )
在线值:
发帖
回帖
粉丝
bithaha 5 2008-2-28 06:29
5
0
本地一个,。。。
上传的附件:
雪    币: 1385
活跃值: (22)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
DLDLIS 2008-3-28 23:37
6
0
A preview version of X-Ways Forensics 14.8 is now available

这个最新版本的X-Ways Forensics 哪里可以下载?
雪    币: 85402
活跃值: (198710)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2008-3-28 23:46
7
0
http://www.x-ways.net/winhex.zip
雪    币: 340
活跃值: (15)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
Squn 2008-3-29 02:18
8
0
忽然发现我用的是12.75版本的、。。。。。
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
gcab 2008-4-4 10:29
9
0
找下中文版一大堆
雪    币: 1708
活跃值: (586)
能力值: ( LV15,RANK:670 )
在线值:
发帖
回帖
粉丝
cntrump 13 2008-4-6 15:23
10
0
怎么没有KEY???

来个14.x的KeyGen
我用的是从官方下的14.9 SR-2对14.8同样有效

上传的附件:
雪    币: 205
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
jacklymin 2008-4-8 00:44
11
0
用看是否比老版的好用
雪    币: 238
活跃值: (12)
能力值: ( LV9,RANK:210 )
在线值:
发帖
回帖
粉丝
cxlrb 5 2008-4-9 14:15
12
0
貌似13.0 SR-12是最后一个支持中文编辑的版本,软件作者故意这么做的,表示不理解。
雪    币: 239
活跃值: (52)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
fffddd 2008-5-2 01:23
13
0
因为国人老搞X他的软件,所以干脆不支持中文了咯。
雪    币: 201
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
axst 2008-5-2 04:28
14
0
忽然发现我用的是12.75版本的、。。。。。
游客
登录 | 注册 方可回帖
返回