EnCase Financial Cr...
 
Notifications
Clear all

EnCase Financial Crime help?

8 Posts
6 Users
0 Reactions
314 Views
(@csusama008)
Eminent Member
Joined: 17 years ago
Posts: 22
Topic starter  

I'm looking for any tips to help me find/recover fiancial documents. I've already recovered folders, ran my keyword search, a file finder, and sorted by file extensions.. any suggestions?

Thanks!


   
Quote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

What kind of "financial documents"? There are the obvious spreadsheets, there can also be reports in Word or PDF or similar. What is the G/L system that is in use? There would certainly be files associated with that. Is there a POS or other customer facing system? What about a backend database? Lots of choices, but just shots in the dark without more info.


   
ReplyQuote
(@csusama008)
Eminent Member
Joined: 17 years ago
Posts: 22
Topic starter  

It's a hard drive taken from a residence, I do not believe the user is computer savue.


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

If they are not computer savvy then they are unlikely to have Quicken or Money and even less likely to have spreadsheets. What do you think should be found? Maybe web pages with some transactions?


   
ReplyQuote
 Earn
(@earn)
Estimable Member
Joined: 20 years ago
Posts: 146
 

Keyword search or create a condition to give you only the specific file types you want to review. I also suggest using the Encase board for Encase specific questions.


   
ReplyQuote
(@jeffcaplan)
Trusted Member
Joined: 21 years ago
Posts: 97
 

I also suggest using the Encase board for Encase specific questions.

I'm looking for any tips to help me find/recover fiancial documents.

^ That doesn't sound like a very EnCase specific question to me.

To the OP, I agree with BitHead already posted - more information is necessary to advise you in which direction you might have luck looking in. In any investigation, there are some steps which you follow all the time, but the majority of the time, you tailor your investigation based on the kind of evidence you are finding.

Jeff


   
ReplyQuote
(@j2222)
Eminent Member
Joined: 20 years ago
Posts: 36
 

Assuming Windows, check what they've been using
- Installed programs
- User MRUs
- Common dialogue box
- Prefetch
- Menus/Desktop for user and all users

etc.


   
ReplyQuote
(@walkabout_fr)
Trusted Member
Joined: 19 years ago
Posts: 67
 

Don't forget to extract and review web history.

It will give you some hints about accesses to local files and documents.

You might find tracks of transactions in the URLs you find. For some banks, the originating account, the target account and the amount being transfered are all included in the URL …

You might also find evidence of online storage access and online applications.


   
ReplyQuote
Share: