Tool review—WinHex

Details

Ressource 1Download: 1-s2.0-S1742287604000295-main.pdf (3346.22 [Ko])
State: Public
Version: Final published version
Serval ID
serval:BIB_5474D294A301
Type
Article: article from journal or magazin.
Collection
Publications
Title
Tool review—WinHex
Journal
Digital Investigation
Author(s)
Casey Eoghan
ISSN
1742-2876
Publication state
Published
Issued date
2004
Volume
1
Number
2
Pages
114-128
Language
english
Abstract
This paper presents strengths and shortcomings of WinHex Specialist Edition (version 11.25 SR-7) in the context of the overall digital forensics process, focusing on its ability to preserve and examine data on storage media. No serious problems were found during non-exhaustive testing of the tool's ability to create a forensic image of a disk, and to verify the integrity of an image. Generally accepted data sets were used to test WinHex's ability to reliably and accurately interpret file date–time stamps, recover deleted files, and search for keywords. The results of these tests are summarized in this paper. Certain advanced examination capabilities were also evaluated, including the creation of custom templates to interpret EXT2/EXT3 file systems. Based on this review, several enhancements are proposed. In addition to these results, this paper demonstrates a systematic approach to evaluating similar forensic tools.
Keywords
Digital forensics tool testing, Digital evidence preservation, Forensic examination, File systems, Data recovery
Create date
16/01/2019 22:22
Last modification date
20/08/2019 15:09
Usage data