|
Helix (Windows)
Documentation
In the documentation options, there are 4 recommended and common reference documents in PDF format that you may need to use in an incident response. An investigator should review them before any forensic investigation.

(Click on image to view bigger version)
The documents are:
- Chain of Custody Form
- Preservation of Digital Evidence
- Linux Forensic Guide for Beginners
- Forensic Examination of Digital Evidence
Browse Contents
Acts like Windows Explorer which allows you to browse the content of the evidence media with this option. Allows you to see the drives, folders, subfolders and files.

(Click on image to view bigger version)
It displays the File Location, Date Created, Date Accessed, Date Modified, Data Attributes (eg, Read Only, Hidden), File Size, CRC and MD5*.
*NOTE: MD5 Hash will only appear if you click on “Calculate MD5 Hash on Files” checkbox
[Continue - Page 6]
|