±Your Account
Membership:
New Today: 0
New Yesterday: 7
Overall: 24203
Visitors: 60±Latest Webinar
±Latest Articles
· Android Forensics
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
±Follow Us
±Latest Jobs
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
Go to page Previous 1, 2
X-Ways 16.9 Timeline Support
Re: X-Ways 16.9 Timeline Support
Posted: Thu Feb 07, 2013 3:12 pm
are you seeing last printed in the metadata column for those documents in the primary directory browser?
-

EricZimmerman - Senior Member
Re: X-Ways 16.9 Timeline Support
Posted: Thu Feb 07, 2013 3:19 pm
Eric, I don't have details at the moment as I'm working on another matter. Sounds like you're immersed in it right now and if you happen to learn anything more about it (including that I'm simply wrong on this), I'm open to your discoveries.
And a supported Event list would be nice.
_________________
Scott Tucker
Aptegra Consulting, LLC
www.aptegra.com
And a supported Event list would be nice.
_________________
Scott Tucker
Aptegra Consulting, LLC
www.aptegra.com
-

TuckerHST - Senior Member
Re: X-Ways 16.9 Timeline Support
Posted: Thu Feb 07, 2013 5:14 pm
Ok, I took a few minutes to check on metadata. In the extract metadata options in Refine Volume Snapshot, as you're probably aware, selecting the checkbox to place metadata in its own column is followed by an "are you sure" dialog box which serves to discourage the user from doing this. Nevertheless, when I say yes and run it again, nothing else happens (at least to the file known to have a "Last Printed" value in its details). I saw this behavior when first trying out the Event list, too. It seems to require running a new volume snapshot, which is obviously less than optimal.
When I took a new volume snapshot, and opted to store metadata in a column, X-Ways successfully extracted a Last Printed date and put it in the metadata column for my test file. However, it still doesn't show up in the Event list.
Incidentally, have you tried sorting the Event list by type? It follows some arbitrary sorting scheme in which Access appears between Modification and Record Change.
In short, this is a great feature-in-progress. It's limited, buggy, and full of promise.
_________________
Scott Tucker
Aptegra Consulting, LLC
www.aptegra.com
When I took a new volume snapshot, and opted to store metadata in a column, X-Ways successfully extracted a Last Printed date and put it in the metadata column for my test file. However, it still doesn't show up in the Event list.
Incidentally, have you tried sorting the Event list by type? It follows some arbitrary sorting scheme in which Access appears between Modification and Record Change.
In short, this is a great feature-in-progress. It's limited, buggy, and full of promise.
_________________
Scott Tucker
Aptegra Consulting, LLC
www.aptegra.com
-

TuckerHST - Senior Member
Re: X-Ways 16.9 Timeline Support
Posted: Thu Feb 07, 2013 5:17 pm
i wouldnt thing a new VS would be required, but youd have to RVS again with that option turned on. the VS would just see the doc file there. at that point it doesnt go into it to get metadata.
ill set up some tests and kick the tires on that specifically.
ill set up some tests and kick the tires on that specifically.
-

EricZimmerman - Senior Member
















