Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsPapersEducationGraduate RecruitmentReviewsInterviewsNewsletterJobsEventsBlog
Search Forensic Focus
Custom Search
Graduate Recruitment

computer forensics graduate jobs

Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!


Helix 3 Enterprise review

Page: 1/2

by Jonathan Krause, Forensic Control Ltd.
www.forensiccontrol.com

Helix 3 Enterprise (H3E) is e-fense’s flagship investigation suite pitched at a similar level as EnCase Enterprise or Access Data Enterprise. It’s aimed at organisations which need to be able to carry out incident response, forensics and e-discovery functions over networks. H3E facilitates centralised incident response, imaging of drives and volatile data and also enables scans and searches of a user’s internet history and documents on any computer which has had the H3E Agent pre-installed on it. The integrity of data in transit and within the H3E database is ensured through 256-bit AES encryption.

H3E’s main differentiator from its competitors is on price and ease of use. Whether this product is financially viable for your organisation is for your personal assessment, as in my experience the prices of such enterprise class products are seldom fixed, being based more upon the individual circumstances in which they are going to be used. So rather than examine value for money, this review focuses on the usability of the product and how well it achieves its stated goals. I was given a time-limited trial version of Release 1 of the 2009 Version of H3E which I tested on a Windows platform.

The Helix 3 Enterprise logo

Install

The main thing I liked about H3E was its relative simplicity in use, and this was certainly true of the installation process. H3E consists of three separate elements (the Agent, the CAT and the Server) each taking less than a minute to install. The Agents sit on the target computers and need to be installed pre-incident if your desire is to maximise the amount of data available for analysis and to minimise any contamination issues which may arise. The other two elements which make up H3E are the Server and the Console Administration Tool (or CAT for short). The H3E manual describes the Server as "the system's headquarters" and the CAT as "the command centre" which seem to me to be very similar functions. I wonder if e-fense could simplify things for the end user by combining the Server and the CAT into a single install process; additionally I see no benefit with invented names to describe old functions; just Agent and Server would seem to be perfectly simple and self-explanatory. The instruction manual reminds you that to ensure you are running the latest version of H3E you should visit h3e.e-fense.com to find up to date downloads but unfortunately at the time of writing this review this resulted in a ‘404 Page Not Found’ error.

The Agents can be installed in a number of ways including through the use of applications such as HP OpenView or PSExec. I installed the Agents manually, which obviously requires physical access to the target machine and an account with administrator-level privileges. Double clicking on the Agent installer package quickly completes the install; I feel options here to rename the default service name (h3e-sma) and to define ports to those of your choosing would be welcome. The CAT installer politely asks where you want the shortcuts to be placed but the Server installer once double-clicked requires no input and finishes rather abruptly with no indication that it has finished or installed correctly.

I was impressed that the H3E Server and CAT can install on Windows, Mac and Linux boxes which gives administrators a good choice of what they can run it from but was less impressed that the Agent can only be run on Windows (post Windows 2000) boxes. Organisations running desktop Macs or Unix derivatives will need additional solutions.

There is a very informative chart in the manual laying out the minimum and recommended specs for running the Agent, the CAT and the Server but as the pdf manual is password encrypted and does not allow extraction of contents unfortunately I’m unable to reproduce it here. However I can say that the minimum requirements for Agents are a Windows 2000 operating system or later, a 400 MHz Celeron processor or equivalent, 256MB RAM and 10MB free disk space. The Server and CAT components would obviously benefit from being on more powerful boxes with the fast network interface.


Use

On starting the CAT, the first thing which struck me was the quality of design of the interface, how easy it was on the eye, its responsiveness and how well it was laid out. A real pleasure to use.


The pleasing interface to the H3E CAT

Once the Agents are installed (keep in mind that you must configure any firewall and the like on your target machines to let the Agents communicate with the CAT and the Server) they should automatically appear under the ‘Agents’ portion of the CAT GUI, on the left in the illustration above; I only knew this (and that I didn’t need to do anything to ‘make’ them appear) after a call to technical support. For me this part is a fundamental part of the application which should really be covered in the manual.

Once the agents were showing that they were available I was able to properly test the capability of H3E. Generating reports including such information as contents of the setipapi.log, screen captures, installed applications, clipboard contents and so on was very straightforward. The key logging capability could also be very useful although I could not find any information as to how much could be stored and what happens when the key logging capacity is reached. Testing the key logger produced the results exactly as I expected but one drawback is it cannot record Unicode characters – for example a simple sentence in Japanese characters typed in on the target machine was recorded on the CAT as ASCII characters.






Next Page (2/2) Next Page


Forensic Education

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: blay189
New Today: 11
New Yesterday: 20
Overall: 13596

People Online:
Members: 5
Visitors: 6
Bots: 10
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

Computer Forensics Examiners- Virginia
Last post by 4n6art in Computer Forensics Job Vacancies on Mar 12, 2010 at 21:00:17

Investigations Manager-China- Salary Neg
Last post by Teval in Computer Forensics Job Vacancies on Mar 12, 2010 at 16:51:00

EDISCOVERY SENIOR ANALYST & MANAGER LONDON
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Mar 11, 2010 at 17:02:47

DATA ANALYTICS & COMPUTER FORENSICS - LONDON, T0 £60000
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Mar 11, 2010 at 16:12:33

Forensic Data Analytics senior associate- London upto 40k +
Last post by ChrisHolt in Computer Forensics Job Vacancies on Mar 09, 2010 at 19:36:48

Digital Forensic Analyst (Fort Worth, Texas)
Last post by pispy4u in Computer Forensics Job Vacancies on Mar 01, 2010 at 00:23:53

Senior Researcher & Research Officer - Staffordshire Uni, UK
Last post by Fab4 in Computer Forensics Job Vacancies on Feb 27, 2010 at 21:19:57

PhD Studentship, Cranfield University, Shrivenham
Last post by charg in Computer Forensics Job Vacancies on Feb 22, 2010 at 14:52:15

Forensic eDiscovery Mgr Global consultancy (London)
Last post by ChrisHolt in Computer Forensics Job Vacancies on Feb 19, 2010 at 16:57:38

Director, Center for Crimminal Justice Training Glenville WV
Last post by JasonMcDougal in Computer Forensics Job Vacancies on Feb 18, 2010 at 14:31:34

Computer Forensics Blog
· Guest blog post: TACTICAL trial by fire
· Computer forensics education directory updated
· Computer forensics education directory now online
· US academic institutions - final call for contact details!
· Hidden Hymn
· Adroit Photo Forensics review
· Interview with Russell May, 4N6 Investigation
· Forensic Computing PhD, UK
· The Value of Push Button Computer Forensics
· Academic institutions - updated

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: HELIX incident response CD
  6: PDA Forensic Tools:An Overview and Analysis
  7: Forensics Plan Guide & Forensic Cookbook
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Handy Recovery

Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.