首页
社区
课程
招聘
[转帖]X-Ways Forensics 15.4
发表于: 2009-8-1 00:32 16488

[转帖]X-Ways Forensics 15.4

2009-8-1 00:32
16488
X-Ways Forensics 15.4

Changelog:

http://www.x-ways.net/winhex/forum/messages/1/2788.html


Download:

http://www.x-ways.net/winhex.zip

[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!

收藏
免费 1
支持
分享
最新回复 (32)
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
2
Posted on Monday, Jul 13, 2009 - 0:46:   

A preview version of X-Ways Forensics 15.4 is now available. The download link can be retrieved by querying one's license status.

What's new?

* Considerably reduced main memory requirements for large volume snapshots (i.e. volume snapshot with a lot of files), allowing to open and analyze volumes with many more million files than in earlier versions (roughly 100% more) with the same amount of available main memory. Please note that the volume snapshot format has changed, so that earlier versions cannot open volume snapshots saved by v15.4 and later.

* Even more deleted files can now typically be found on NTFS volumes and included in the refined volume snapshot when running the particularly thorough file system data structure search. This deleted files can be listed with filenames, path, timestamps etc. Forensic license only.

* Often X-Ways Forensics can now also retrieve a true deletion timestamp for previously existing files during the particularly thorough file system data structure search. Even more deletion timestamps can be found when viewing/previewing $UsnJrnl:$J. These is a very unique features, available for NTFS volumes. Forensic license only. Please don't confuse it with so-called deletion timestamps that other forensic tools may show you on NTFS volumes, for files that have not even been deleted from the file system.

* Option to exclude deleted files from volume snapshots when the they are taken. Useful if you are interested or not supposed to look at deleted files.

* Option to exclude the time-consuming search for FILE records outside of the $MFT from the particularly thorough data structure search in NTFS.

* It's now possible to see and copy the hit counts for selected search terms in the search term list. These hit counts are based on the current settings for the search hit list that is on the screen, take all filters into account, the explored path, any active AND combination etc. Forensic license only.

* It is now possible to search for more than 1 search time at a time in an index search. (In this preview version, the edit box for the search terms does not yet work exactly as it is meant to work.) It is now also possible to control the substring and word extension options for index searches run from within the case root window. Forensic license only.

* Improved detection of the sector size and different Apple partition table layouts in CD/DVD raw images.

* Support for HFS+ volumes on optical discs or in images with a sector size of 2048 bytes. Forensic license only.

* Ability to change the attributes "temporary" and "not indexed" of a file in File | Properties, using the letters T and X, respectively.

* Several minor improvements.
2009-8-1 00:32
0
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
3
Posted on Tuesday, Jul 21, 2009 - 17:52:   

v15.4 Beta:

* The Back and Forward commands in the Position menu and the Back and Forward buttons in the toolbar now allow to conveniently go back to a certain directory browser setting. This takes into account: explored path, recursive or non-recursive, sort criteria, on/off state of all filters, settings of some of the filters, some directory browser options. The Back and Forward commands also allow to activate the previously active data window again when switching between windows (does not work for viewer windows yet). Forensic license only.

* The filters have been given some "intelligence" when navigating from a parent file to a child file or vice-versa, so that the filters "know" when it's a good time to be turned off. Forensic license only.
For example:
- If you are using a filter to focus on all extracted e-mail messages recursively, and then you double-click an individual e-mail message to have a look at its attachments in the directory browser, the filter is automatically deactivated, so that you can actually see these attachments. A simple click on the Back button returns to the previous point of exploration and restores the previous filter settings and the last selection, so that you can easily continue reviewing the next e-mail message!
- If you are using a filter to focus on videos or documents, and then you double-click a video or a document to see the video stills exported for that video or the embedded pictures in that document, respectively, the filter is automatically deactivated, too.
- When you are viewing video stills only, in a gallery, and you use the Backspace key or "Find parent object" menu command to navigate to the video that this still belongs to (e.g. in order to play that video), then any active filters will be turned off so that the video can actually be listed. A simple click on the Back button returns to the previous overview of stills, enables the previous filters again, and restores the last selected item, so that you can easily continue with the next still!
- This works analogously when systematically looking at e-mail attachments, if occasionally for relevant attachments you would like to view the containing e-mail message (and e.g. print it or include it in a report) and then return to the list of attachments.

These two new features combined, intelligent filters on the one hand and back/forward navigation in the directory browser on the other hand, are expected to further improve the usability of the software tremendously.

* It is now possible to explore directories and files with child objects listed in the case root window, e.g. by double-clicking them. For that, the data window will automatically be activated that represents the evidence object that contains the directory or file. With the Back command you can conveniently return to the case root window.

* Improved StreamMRU decoding for the registry report to reveal folders on removable media.

* Error in index search in v15.4 Preview fixed.

* Toggling decimal and hexadecimal offsets by clicking the offset column stopped working in certain situations in v15.2 and v15.3. This was fixed.

* Various minor improvements.
2009-8-1 00:33
0
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
4
Posted on Friday, Jul 31, 2009 - 3:05:   

v15.4 was just released.


It also seems to have fixed an issue with Recovery/Copy of long filenames.

We are working a case where we are extracting lots of files out of about 50 images. With the previous release we were seeing a handful of files that were failing to export due to filename (or path) too long. (Nice error messages and report associations, but none the less, no files even though the paths were less than 540 chars).

We've tested several of the problematic files with 15.4 this morning and no issues. Thanks for fixing it before we had time to complain. (And I'm glad we renewed our maintenance just in time to get the new functionality.)
2009-8-1 00:33
0
雪    币: 546
活跃值: (1692)
能力值: ( LV12,RANK:210 )
在线值:
发帖
回帖
粉丝
5
发一个keygen 吧:
附件下载: X-Ways.WinHEX.v15.x_KeyGen-FFF.rar

期待汉化。
上传的附件:
2009-8-3 06:39
0
雪    币: 1340
活跃值: (1502)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
winhex不等于Forensics
2009-8-3 16:58
0
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
7
Google 的结果.

x-ways forensics 综合数据分析套件 快速入门

http://www.china-forensic.com/xways/chapter/1.html
2009-8-3 18:38
0
雪    币: 1340
活跃值: (1502)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
8
[QUOTE=linhanshi;665627]Google 的结果.

x-ways forensics 综合数据分析套件 快速入门

http://www.china-forensic.com/xways/chapter/1.html
[/QUOTE]
原来下载过一个 forensics ,版本比较低 它就是winhex的一个扩展 相当于winhex+不少的插件 但是界面还是winhex 用keygen 生成 forensics 号注册就会发现运行缺少文件  forensics 必须注册用户才可以下的 大家下的都是winhex 少文件的...
2009-8-4 13:32
0
雪    币: 242
活跃值: (30)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
[QUOTE=我是土匪;665289]发一个keygen 吧:
附件下载: X-Ways.WinHEX.v15.x_KeyGen-FFF.rar

期待汉化。[/QUOTE]

有中文语言包。。。。。。。。。。
2009-8-4 13:46
0
雪    币: 2307
活跃值: (1023)
能力值: (RANK:350 )
在线值:
发帖
回帖
粉丝
10
[QUOTE=linhanshi;665627]Google 的结果.

x-ways forensics 综合数据分析套件 快速入门

http://www.china-forensic.com/xways/chapter/1.html
[/QUOTE]

已将帮助打包,主要是测试HELP & MANUAL 软件。
上传的附件:
2009-8-4 16:36
0
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
11
Thanks for share.
2009-8-5 20:32
0
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
12
X-Ways WinHex v.15.4 SR-2 out now :

http://www.x-ways.de/winhex.zip
2009-8-5 20:33
0
雪    币: 510
活跃值: (478)
能力值: ( LV7,RANK:100 )
在线值:
发帖
回帖
粉丝
13
这东西的狗不好搞,,R4ND的,用了N多算法。
2009-8-6 15:10
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
14
我汉化过15.1版本的
2009-8-7 09:06
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
15
现在没时间汉化这个了
2009-8-7 09:08
0
雪    币: 203
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
16
测试一下,谢谢楼主...
2009-8-7 09:44
0
雪    币: 203
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
17
只有取证版的援权才能有那么多的功能啊。可惜。偶现在用的是15.1 的。
2009-8-7 09:52
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
18
大牛好多,这个工具不错。。。
2009-8-7 15:04
0
雪    币: 190
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
19
感谢  找不到Forensics
2009-8-9 21:17
0
雪    币: 915
活跃值: (1998)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
20
谢谢楼主 好东西啊
2009-8-10 17:31
0
雪    币: 915
活跃值: (1998)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
21
这个不是真正的X-Ways Forensics啊

不过也支持 发个KeyGen和中文语言包 用X-Ways Forensics的授权才能使用中文语言
上传的附件:
2009-8-10 17:39
0
雪    币: 301
活跃值: (300)
能力值: ( LV9,RANK:290 )
在线值:
发帖
回帖
粉丝
22
这个版还是不能正常显示中文,唉,原来听说x-way版本从没有中文的问题呢,还是用老版的winhex安心。
2009-8-15 17:48
0
雪    币: 199
活跃值: (17)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
23
之前的版本 ASCII 能正常显示中文
现在新版虽然可显示中文 Unicode . 但是 ASCII 却不正常了.
2009-8-16 11:33
0
雪    币: 98674
活跃值: (200999)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
24
WinHex 15.4 SR-5 has been released.
2009-8-31 11:36
0
雪    币: 433
活跃值: (1870)
能力值: ( LV17,RANK:1820 )
在线值:
发帖
回帖
粉丝
25
thanks for share
2009-8-31 12:32
0
游客
登录 | 注册 方可回帖
返回
//