PDA

View Full Version : A slightly different forensics version of KNOPPIX - HELIX



r00ster
01-21-2004, 05:56 PM
I have posted the newest version of HELIX to my website. It is available to anyone who is interested in forensics and incident response. HELIX will be used for forensics training at SANS for Track 8. HELIX has acpi/firewire/usb built into the kernel so it will work on most laptops that require acpi like the Sony R505.

Helix focuses on forensics and incident response. You can obviously boot HELIX just like Knoppix but it has been modified for forensics use so it will not mount swap space no matter what and it will force you to make a time zone selection. It also has an autorun feature for windows specifically for live imaging and incident response.

You can get the iso from http://www.e-fense.com/tools

atihun
02-12-2004, 05:35 PM
Thank you!

This is an excellent resource.

Not only does it boot with my Sony Vaio C1MW which uses a Firewire CDROM, but it has some great forensics tools and capabilities.

Thanks again!

Attila :D