Notifications
Clear all

.doc metadata

11 Posts
7 Users
0 Reactions
1,947 Views
(@paulo111)
Eminent Member
Joined: 17 years ago
Posts: 36
Topic starter  

Are there any tools (ideally free) that will identify from within a word document (.doc file) metadata that will tell us where a file has been previously saved and which user edited by?

Any tools you can recommend or manual review techniques would be a good help.


   
Quote
(@paulo111)
Eminent Member
Joined: 17 years ago
Posts: 36
Topic starter  

I got my pointers from reading this document

http//www.computerbytesman.com/privacy/blair.htm

I just wondered if their are any tools that will automate the analysis, and if so what are the best tools called?


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Wmd.pl and oledmp.pl, both found on the DVD that accompanies the Windows Forensic Analysis book, replicate what the ComputerBytesMan's tool does.

Both are free, both are open source, and I've used both repeatedly to assist me in my own examinations.


   
ReplyQuote
(@paulo111)
Eminent Member
Joined: 17 years ago
Posts: 36
Topic starter  

Thanks Keydet89, will your tools also work on .docx


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

No, they won't. As you're well aware, .docx is not OLE/structured storage format…it's XML and packed/zipped.


   
ReplyQuote
(@paulo111)
Eminent Member
Joined: 17 years ago
Posts: 36
Topic starter  

No, they won't. As you're well aware, .docx is not OLE/structured storage format…it's XML and packed/zipped.

Yes a tool that could do similar for docx would be great for the forensic community. Theres very little published on docx for forensics. If you have any books or articles that cover these files I will look into buying them.


   
ReplyQuote
(@thefuf)
Reputable Member
Joined: 17 years ago
Posts: 262
 

http//gnunet.org/libextractor/
http//hachoir.org/

See also http//www.forensicswiki.org/wiki/ToolsDocument_Metadata_Extraction


   
ReplyQuote
(@gtorgersen)
Trusted Member
Joined: 17 years ago
Posts: 70
 

If you can find someone who is somewhat decent at .net programming they could get that information very easily. If I find time maybe I will put that together for the community unless there is something already out that will gather all the metadata?


   
ReplyQuote
(@seanmcl)
Honorable Member
Joined: 19 years ago
Posts: 700
 

Yes a tool that could do similar for docx would be great for the forensic community. Theres very little published on docx for forensics. If you have any books or articles that cover these files I will look into buying them.

There is very little metadata in .docx files compared to .doc files and it is easy to find. Simply unzip the file and use your favorite text editor to read the file docProps/core.xml.

All the metadata is in there.


   
ReplyQuote
PaulSanderson
(@paulsanderson)
Honorable Member
Joined: 19 years ago
Posts: 651
 

There is a free OLE deconstructor program on my web site www.sandersonforensics.com that was posted as a result of my presentation at the Microsoft LE conference in the UK last year.


   
ReplyQuote
Page 1 / 2
Share: