Tool review—WinHex

Détails

Ressource 1Télécharger: 1-s2.0-S1742287604000295-main.pdf (3346.22 [Ko])
Etat: Public
Version: Final published version
ID Serval
serval:BIB_5474D294A301
Type
Article: article d'un périodique ou d'un magazine.
Collection
Publications
Titre
Tool review—WinHex
Périodique
Digital Investigation
Auteur⸱e⸱s
Casey Eoghan
ISSN
1742-2876
Statut éditorial
Publié
Date de publication
2004
Volume
1
Numéro
2
Pages
114-128
Langue
anglais
Résumé
This paper presents strengths and shortcomings of WinHex Specialist Edition (version 11.25 SR-7) in the context of the overall digital forensics process, focusing on its ability to preserve and examine data on storage media. No serious problems were found during non-exhaustive testing of the tool's ability to create a forensic image of a disk, and to verify the integrity of an image. Generally accepted data sets were used to test WinHex's ability to reliably and accurately interpret file date–time stamps, recover deleted files, and search for keywords. The results of these tests are summarized in this paper. Certain advanced examination capabilities were also evaluated, including the creation of custom templates to interpret EXT2/EXT3 file systems. Based on this review, several enhancements are proposed. In addition to these results, this paper demonstrates a systematic approach to evaluating similar forensic tools.
Mots-clé
Digital forensics tool testing, Digital evidence preservation, Forensic examination, File systems, Data recovery
Création de la notice
16/01/2019 22:22
Dernière modification de la notice
20/08/2019 15:09
Données d'usage