Notifications
Clear all

EnCase 6

15 Posts
9 Users
0 Reactions
2,060 Views
(@armresl)
Noble Member
Joined: 21 years ago
Posts: 1011
 

There are not a lot of times where one cab be 100% sure that the MAC times have not been altered.

Usually, you would want to take other events and build it around your main evidence. email, chat logs, installing of windows service packs, internet history, p2p, etc.


   
ReplyQuote
(@sijune)
Active Member
Joined: 18 years ago
Posts: 7
 

In 2 of my evidences i cannot view the sys.evt files, event viewer says they are corrupted, the rest 4 are fine.

Could this mean something ?

armresl, your answer i am afraid is to general.


   
ReplyQuote
(@sijune)
Active Member
Joined: 18 years ago
Posts: 7
 

Lots of files in Encase, although they are e-mails or documents they appear with different strange names .gif, .jpg etc.

Why is that happenning and how can i bring them back to they original form ?

Thanx


   
ReplyQuote
 Earn
(@earn)
Estimable Member
Joined: 20 years ago
Posts: 146
 

Sounds like you need to take a Encase training class.


   
ReplyQuote
(@jonathan)
Prominent Member
Joined: 20 years ago
Posts: 878
Topic starter  

Lots of files in Encase, although they are e-mails or documents they appear with different strange names .gif, .jpg etc.

Why is that happenning and how can i bring them back to they original form ?

Thanx

Not quite sure, but have you run the "Verify File Signatures" option under the search tab?


   
ReplyQuote
Page 2 / 2
Share: