X-Ways Forensics/ WinHex Manual

X-Ways Forensics/ WinHex Manual

X-Ways Software Technology AG is a stock corporation incorporated under the laws of the Federal Republic of Germany. WinHex was first released in 1995. This manual was compiled from the online help of WinHex/X-Ways Forensics v15.1 SR-4, released October 2008. It is available in English and German. Supported operating systems: Windows 2000, Windows XP (recommended), Windows 2003 Server, Windows Vista/2008 Server (both with a few limitations).

We would like to thank the state law enforcement agency of Rhineland-Palatinate for extraordinarily numerous and essential suggestions on the development of X-Ways Forensics and X-Ways Investigator.

Here are some instructions to help you get started and find some important features: Create a case, add an evidence object (such as your own C: drive or hard disk 0, or an image file). In the directory tree, you may use a right click to list the contents of a directory in the directory browser including all its subdirectories. At the same time you can use a dynamic filter (e.g. list files based on filenames, true file type, size, timestamps, etc.) using Options | Directory Browser. The powerful logical search functionality can be found in Search | Simultaneous Search. The indexing feature can be found in the Search menu, too. More interesting functions in X-Ways Forensics can be found in the context menu of the directory browser (e.g. the ability to copy files off an image) and in the Specialist menu, in particular “Refine Volume Snapshot”). The latter allows you to further process files automatically, e.g. explore zip archives, check pictures for the amount of skin tones, check documents for encryption, etc. etc

Get pdf X-Ways Forensics/ WinHex Manual

Sprintwealth