Notifications
Clear all

Index.dat recovery

7 Posts
6 Users
0 Reactions
686 Views
(@jaytee)
New Member
Joined: 14 years ago
Posts: 4
Topic starter  

Hi,

I have been tasked with trying to find and recover any deleted index.dat files from an eo image, we appear to have an EnScript package McCallum Petterson Enscript suite which has an ‘Internet history parser- carver’ but this is for EnCase v4.

Does anyone know of any similar script which will work with EnCase 6.18?

Jay


   
Quote
(@angrybadger)
Estimable Member
Joined: 18 years ago
Posts: 164
 

Hi,

I have been tasked with trying to find and recover any deleted index.dat files from an eo image, we appear to have an EnScript package McCallum Petterson Enscript suite which has an ‘Internet history parser- carver’ but this is for EnCase v4.

Does anyone know of any similar script which will work with EnCase 6.18?

Jay

Encase "Search for Internet History" in "comprehensive search" mode?


   
ReplyQuote
ehuber
(@ehuber)
Trusted Member
Joined: 17 years ago
Posts: 91
 

It's not a script, but I highly recommend the Net Analysis\HSTEX combo for this sort of work.


   
ReplyQuote
pr3cur50r
(@pr3cur50r)
Eminent Member
Joined: 15 years ago
Posts: 28
 

If it's Encase you are using, perhaps try running recover folders and file finder across the image. If you manage to recover any then copy/unerase and then import to netanalysis. I have never used Hstex but this looks like it might be fruitful! D


   
ReplyQuote
(@douglasbrush)
Prominent Member
Joined: 16 years ago
Posts: 812
 

It's not a script, but I highly recommend the Net Analysis\HSTEX combo for this sort of work.

Agreed. While EnCase has it's place I have not found it's browser history to be a strong point. HstEx will carve an image very fast and the results can be displayed in NetAnalysis very easily to sort, filter, etc.


   
ReplyQuote
(@detkoehle)
New Member
Joined: 18 years ago
Posts: 2
 

I have to agree that HSTEX is great for finding deleted internet history while NetAnalysis will give you a wealth of information for Internet History. It's well worth the $300.00 (Not sure of the price anymore). If you only have EnCase then the previous suggestions by the other posters are spot very helpful.


   
ReplyQuote
(@douglasbrush)
Prominent Member
Joined: 16 years ago
Posts: 812
 

Though in all fairness to the original post, the question was about recovering the index.dat files.

In EnCaes it can be a little buried but under case processor -> information finders -> File Finders you will get to where you can carve for crap (technical term).

You can add a file type (headers/footers) or Import from File Signatures Table and find the Internet sigs and there are options for dat files.


   
ReplyQuote
Share: