Welcome to computer forensic portal - your online resources to all computer foreniscs
 
Knowledge Articles
Books Database
Legal Cases
Forensic Dictionary
PDF documents
Web Resources
FAQ

 

Helix (Linux)
Page 1
Page 2
 
Computer Forensic Tools
Image Acquisition
Expert Witness
Helix (Windows)

 

  Home > Knowledge Articles > Helix (Linux)

Helix (Linux)

Helix has a friendly user-interface that is easy to use and navigate. Most of the needed functions can be found on the task bar located on the bottom of the screen.

(Click on image to view bigger version)

Getting Started

Helix Menu

Run Program: Opens a run command window to quickly launch programs. (Similar to "Run..." function in Windows)
Terminal: Opens a terminal window to run command. It accesses the computer as user "knoppix". (Similar to "cmd.exe" function in Windows)
Mount Manager: It is a GUI to manage access to storage devices connected to the computer.
Rescan Devices: Rescans the computer for more devices that are not automatically detected. Useful when connecting new devices on the system.
Forensics: Provides applications to facilitate digital forensic investigations.
Adepto Instantly perform image acquisition and generate chain of custody. Air (Automated Image and Restore) - Image and restore can be done easily with a few clicks via GUI.
Air (Automated Image and Restore) Image and restore can be done easily with a few clicks via GUI.
Linen Allows investigator to acquire any device from a Linux computer and it provides an alternative method to acquire device over Windows or DOS.
Retriever Quickly scans any mounted device for images or videos found on the device and it comes with a viewer.
Autopsy With GUI, it aids in analyzing Windows or UNIX file systems.
pyFlag Designed to simplify forensic investigations and log file analysis.
Regviewer Allows examination registry files from any platform.
Hexeditior Examines file's binary and allows editing to a file's hex and ASCII codes.
Xfce Diff Enables investigator to view files side by side.
Xhfs With GUI, it aids investigator to browse and copy files on a HFS-formatted volume.
Manuals Includes manuals help for pyFlag, RAID-Reassembly, Partition-Info and Sleuthkit-Informer Articles.
Incident Response Provides applications for use in an incident response.
Ethereal Allows investigator to browse network traffic.
ClamAV A preferred anti-virus tool to scan e-mails and mails gateways.
R-Prot An anti-virus tool to scan the computer of viruses, worms and malicious software.
Office Includes common office applications like PDF Viewer, Writer (Word), Impress (PowerPoint) and Calc (Excel) to assist you in screening files or documentation.

 

File Manager

Just like Windows Explorer in Windows OS, you can view your files and folders.

Root Terminal

It is terminal (see above), with root access.

Desktop Switcher

Allow you to switch easily between the two or more desktops.

Web Browser

Opens Firefox web browser.

Text Editor

Similar to NotePad in Windows, it allows you to jot down investigation notes and save.

Print

Allow you to add or connect to a printer to print documents or investigation notes recorded.

CPU Utilization Graph

It is a simple graph that shows the CPU usage.

Memory Utilization Graph

It is a simple graph that shows the RAM usage.

Network Utilization Graph

It is a simple graph that shows the network activity on the device.

Disk Performance Monitor

It is a simple graph that shows the hard-disk usage.

Volume, Exit and Time performs the normally expected functions.

[Back - Page 1]

Back to Top

 

© 2009
Computer Forensics Portal
All Rights Reserved

Disclaimer | Privacy Policy

Home | Contact | Sitemap

Knowledge Articles | Books Database | Legal Cases | Forensic Dictionary | Web Resources | Frequently Asked Questions