Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

Latest Forum Posts

Computer Forensics Videos

WinHex, X-Ways Forensics, X-Ways Investigator 14.4 released
AnnouncementsWHAT'S NEW?

* Ability to extract e-mail messages and attachments from AOL PFC files. (forensic license only) Note that if these files have no extension, only a signature check will identify them as PFC files.

* Can now extract embedded files from MHT Web Archives if you append ";*.mht" to the series of file masks for e-mail extraction. (forensic license only)

* NTFS permissions can now be seen in Details mode...

* The internals of the NTFS file system journal $LogFile can now be viewed with the View command and in Preview mode.

* For NTFS volumes, the Technical Details Report now shows the volume GUID, the NTFS version number, and the volume flags.

* Windows Prefetch files can now be conveniently viewed.

* For Windows shortcut files (.lnk), any MAC addresses shown are now definitely MAC addresses. The creation date+time of the target's object ID is now also shown. Volume ID, birth volume ID and object ID are now displayed in special GUID notation.

* There is now an option to copy/append file metadata to the comments of selected files, when editing the comments, which allows to later filter by this metadata with the comments filter, to export the metadata with the Export List command, and to output it with a report table in a case report. (forensic license only) Metadata can be extracted from Windows shortcut files (.lnk), OLE2 compound files (e.g. pre-2007 MS Office), and .shd printer spool files. More file types to be added in the future.

* The buffer size for comments in the case report has been increased. Line breaks in comments are now converted to HTML line breaks for the case report.

* More space for the user-specified comments on a file when printing with a cover page.

* It's now possible to conveniently send the files in an evidence object's volume snapshot to an external virus scanner. (forensic license only) Infected files will be added to a report table named "Virus suspected". The command can be found in the Specialist menu. Please see the program help for details.

* It is now possible to export report table associations when creating a container, so that the recipient of the container can already see classifications such as "notable", "invoice", "family", "bomb construction", etc. when adding the container to a case.

* Files that were recognized as irrelevant with the help of the hash database can now be optionally excluded from further volume snapshot refinement operations. This has an immediate effect if hash database matching is selected at the same time with other options such as skin color computation, search for embedded pictures etc.

* In a search hit list, it is now possible to recover/copy the files that contain the selected search hits automatically into subdirectories that are named based on the respective search term. For that, please try the new third state of the checkbox entitled "Recreate full original path".

* There is a new command in the Position submenu of the context menu in the search hit list of a volume that allows to conveniently exit the search hit list and navigate to the respective file in its directory.

* Search hits based on code page 1251 (Cyrillic) are now displayed correctly in the search hit list. (since v14.3 SR-5)

* Manually mixing different index .xfi files in the same index subdirectory (undocumented feature) now works reliably. E.g. like that you can have multiple indexes based on the same character set, like an index of words (a-zA-Z) and an index of numbers (0-9), and search all of them simultaneous- ly. (since v14.3 SR-4)

* Empty indexes with no words will no longer be saved as xfi files. As a result, there will be no annoying error messages about empty indexes any more when searching an index. An evidence object's index may be empty e.g. if you index tagged files only and the tagged files do not contain any text, have a size of zero bytes, etc.

* It is now possible to optionally include substrings in index searches from the case root. The option to include substrings in indexes did not work for Unicode in the original v14.3 release. This was fixed with v14.3 SR-1.

* In substring-enabled indexes created with v14.3 SR-1 and later, XWF can now optionally search for whole words only (more precisely, beginnings of words). This prevents finding e.g. "card" in "bankcard". Useful if there are too many hits in such solid compound words and you are more interested in the word as a whole word.

* Fixed an error that could occur when running an index search from the case root window.

* Fixed an error that could occur under certain circumstances when starting indexing.

* Ability to copy selected data has hex values in GREP notation.

* Under Windows Vista, the lower half of a decoupled data window no longer becomes invisible when reintegrated in the main window.

* When extracting embedded JPEG files from other files, X-Ways Forensics is now more strict when deciding what actually is a JPEG file and what only looks like one.

* Including directories in a recursive view is now a 3-state option. In its middle state, real directories are not included, but archives treated as directories are.

* The internal file header signature search algorithm can now automatically detect the original size of Outlook PST, AOL PFC, Prefetch, EMF, and SPL files.

* Ability to find additional sessions on multi-session CDs burned with Roxio software with a thorough file system data structure search if CDFS does not co-exist with UDF.

* Ability to understand certain dynamic disks created by Windows Vista that are incompatible with earlier Windows versions.

* Full support for NTFS volumes with exotic FILE record sizes. (since v14.3 SR-5)

* If the viewer component freezes when decoding the text in a file for the logical search or for indexing, X-Ways Forensics will now continue with the next file after a time- out period has expired, and will add the offending file to the report table "Unable to decode text."

* A Japanese translation of the user interface of X-Ways Forensics is now available from our Japanese reseller, Data Recovery Center.

* Maximum number of report tables in a case now 100 instead of 64.

* Earlier versions of X-Ways Forensics left it to the user to decide whether to search for file header signatures in partitioned space on a physical partitioned evidence object as part of the Refine Volume Snapshot operation. This option has been removed, and the search is now run in partitioned space only within the partitions themselves, to avoid unnecessary duplication.

* Further limitations of the reduced user interface of X-Ways Investigator can now optionally be specified individually for certain users even in a shared installation, by creating copies of the investigator.ini file named "investigator *.ini", where * is the respective username.

* X-Ways Investigator no longer allows to open a case whose case directory is missing. WinHex and X-Ways Forensics still allow to do this.

* Several other minor improvements and error corrections.

* XWF now deals more gracefully with truncated FAT partitions in incomplete image files. (since v14.3 SR-1)

* New directory icons. Dedicated icon for deleted partitions in the case tree and in the case root window. (since v14.3 SR-3)

* Ability to delete the case log from within X-Ways Forensics. (since v14.3 SR-3)

* The Java date+time format now respects the Data Inter- preter's Big Endian option. That date+time format can be found in Little Endian in BlackBerry memory dumps. Before, it simply always worked based on Big Endian philosophy. (since v14.3 SR-4)

* Fixed an error that could prevent to correctly open certain extremely fragmented alternate data streams on NTFS. (since v14.3 SR-4)

* Fixed display refresh problem in case root window. (since v14.3 SR-4)

* The definitions in File Type Signatures.txt and File Type Categories.txt have slightly changed in that Unix/Linux executable files now have the type "elf" instead of "elfexe", and Windows Vista Event Log Files now have the type "evtx" instead of "elf". (since v14.3 SR-4)

* Fixed an error that under very special circumstances caused WinHex/X-Ways Forensics to show existing partitions as lost partitions. (since v14.3 SR-6)
Posted by forensicfocus on Thursday, October 04, 2007 (12:06:57) (2012 reads)
"WinHex, X-Ways Forensics, X-Ways Investigator 14.4 released" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

Related Links
 More about Announcements

Most read story about Announcements:
Interview with Sam Raincock, SRC
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad

Options

 Printer Friendly Page  Printer Friendly Page

 Send to a Friend  Send to a Friend

Forensic Education

computer forensics education choices COURSE DIRECTORY

User Info

Welcome Anonymous

Nickname

Membership:
Latest: praf
New Today: 4
New Yesterday: 19
Overall: 15533

People Online:
Members: 3
Visitors: 13
Bots: 4
Staff: 0
Staff Online:

No staff members are online!
Latest Jobs

Computer Forensic - Associate - London - £45,000-£55,000pa+
Last post by ForensicsRecruiter in Computer Forensics Job Vacancies on Sep 01, 2010 at 14:34:53

Computer Forensic Specialist - Team Lead - London £55-£80k+
Last post by ForensicsRecruiter in Computer Forensics Job Vacancies on Sep 01, 2010 at 14:23:04

COMPUTER FORENSIC/EDISCOVERY CONTRACT ROLE, LONDON 4-8 WEEKS
Last post by ScottBurkeman in Computer Forensics Job Vacancies on Aug 27, 2010 at 16:29:03

Computer Forensic Vacancy South Wales
Last post by stezer2000 in Computer Forensics Job Vacancies on Aug 19, 2010 at 09:41:54

CF Investigator (LE experience). London
Last post by DavidSullivan in Computer Forensics Job Vacancies on Aug 18, 2010 at 17:00:41

Computer/Video Forensic Examiners (Fredericksburg, VA, USA)
Last post by snorris in Computer Forensics Job Vacancies on Aug 18, 2010 at 00:09:50

Senior Forensic Computer Examiner - London
Last post by pgro in Computer Forensics Job Vacancies on Aug 17, 2010 at 13:26:19

Phd studentship available at University of Surrey.
Last post by apurva.rustagi in Computer Forensics Job Vacancies on Aug 16, 2010 at 22:52:52

Consultant- London- £25K-£40K
Last post by Teval in Computer Forensics Job Vacancies on Aug 05, 2010 at 07:37:45

Forensic Consultant - Singapore
Last post by darrencerasi in Computer Forensics Job Vacancies on Aug 05, 2010 at 01:00:18

Computer Forensics Blog
· 'Web 2.0' as evidence
· Scalability: A Big Headache
· Single Sign On
· Authentication and Authorisation
· UK student competition: Win free training on "Investigating Connection Records" course
· 10% Discount on Connection Records/Intro to CSA Training (UK)
· Mobile Forensics Training: Investigating Connection Records (UK, Aug 23/24)
· Windows Search forensics
· Computer Forensics - sometimes it’s all about timing
· Forensic Focus 2010 survey

read more...
Members' Blogs

Start Blogging

What is Computer Forensics?
Computer forensics (or forensic computing) is the use of specialized techniques for recovery, authentication, and analysis of electronic data with a view to presenting evidence in a court of law.
Computer Forensics Downloads
  1: Forensic Examination of Digital Evidence: A Guide for Law Enforcement (pdf)
  2: ACPO Good Practice Guide for Computer based Electronic Evidence
  3: Electronic Crime Scene Investigation: A Guide for First Responders (pdf)
  4: Ancysoft Data Recovery Software
  5: Forensics Plan Guide & Forensic Cookbook
  6: HELIX incident response CD
  7: PDA Forensic Tools:An Overview and Analysis
  8: Recover My Files
  9: Autopsy Forensic Browser Version 2.03 (source code)
  10: Handy Recovery
Forensic Focus

Forensic Focus

Copy and paste the text below to insert the button displayed above on your site. Thanks for your support!


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.