Looking for advise ...
 
Notifications
Clear all

Looking for advise on purchase

4 Posts
3 Users
0 Likes
303 Views
(@bambam)
Posts: 3
New Member
Topic starter
 

Looking to add to my tool kit and looking for advise.

I currently have X-Ways forensics. I've been a long time reader of these forums and purchased x-ways based on the positive comments I have seen here and have not been disapointed.

I am considering Encase, FTK, Prodiscover and Paraben. I am open to other recommendations.

I mostly examine windows based systems but I am seening more mac's so I'd like to have mac support though it is not deal breaker. Phone/PDA support would be nice too (I know encase has an add-on for this – Anyone tried it?).

Email seems to be the primary focus for clients and I have run into some problems with X-Ways. It does not support viewing OST's over 2gb (or any file over 2 GB) and even with smaller OST files I have some problems (I have a 1GB OST that I can see the email index but cannot get it to show any of the emails). Do any of the above support viewing 2GB+ ost files and extracting emails without first having to extract the ost and use a o********t converter? Would I be better off just extracting the OST/PST regardless of which product I purchase and then import/open the file in a VM with Outlook? How well do these products deal with corrupt/damaged ost/pst files?

Ideally it would be nice to be able to export selected emails to some sort of file like a PST for delivery to the client but this is not a requirement.

FTK was going to be my next purchase but with 2.0 and the reported problems along with the price hike I'm rethinking what to buy. It appears that 2.1 is much better though.

I realize that there are many factors to consider and there is no one perfect tool for all jobs but any advise on which tools handle email best would be appreciated.

The hardware I will be using is a Xeon 5410 based system with 8GB RAM and a hardware RAID running 2003 server.

Thank You.

 
Posted : 14/05/2009 3:09 am
(@kovar)
Posts: 805
Prominent Member
 

Greetings,

I use NEMX and Aid4Mail to handle email, no matter what primary forensic tool I'm using. I've never been happy with how FTK or EnCase handle PST and DBX files.

I used to use FTK but switched to EnCase during the 2.0 fiasco. I just installed FTK 2.2 and may start using it.

FTK has a more intuitive user interface. EnCase has Enscripts. FTK has dtSearch. EnCase has logical evidence files and the File Mounter script.

If I had to go buy one or the other on a limited budget, I'd go with EnCase and, in fact, that is what I did a few months ago. (I'm now working for a client with a much bigger budget.)

-David

 
Posted : 14/05/2009 4:03 am
(@mitch)
Posts: 135
Estimable Member
 

I must agree with Kovar, I would go with EnCase.

regards

 
Posted : 15/05/2009 2:13 pm
(@bambam)
Posts: 3
New Member
Topic starter
 

Thank you both for your input. I was leaning towards Encase. Aid4Mail looks useful and the forensic license is very reasonably priced.

 
Posted : 02/06/2009 8:58 pm
Share: