Nokia Lumia 800 [WP...
 
Notifications
Clear all

Nokia Lumia 800 [WP7]

33 Posts
11 Users
0 Reactions
5,856 Views
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 13 years ago
Posts: 576
 

Paul,

I converted the Store.vol file to a plain text file first by changing the file extension to .txt. I did not find anything of interest in the Store.txt file.

Then I used a Hex viewer to search the file Store.vol for interesting text and did not find any.

Apparently I should have used another tool?


   
ReplyQuote
(@rampage)
Reputable Member
Joined: 17 years ago
Posts: 354
 

Hi, ESE databases can be parsed using log2timeline/plaso
just feed the file to the tool and it will generate a timeline of elements contained in the ese file.

or take a look here for more informations

http//forensicswiki.org/wiki/Extensible_Storage_Engine_%28ESE%29_Database_File_%28EDB%29_format


   
ReplyQuote
PaulSanderson
(@paulsanderson)
Honorable Member
Joined: 19 years ago
Posts: 651
 

Hi UA

Not when I replied, but I have since released a Browser extension for my Forensic Toolkit for SQLite to allow my users to browse an EDB/ESE file with my Forensic Browser component.

http//sandersonforensics.com/forum/content.php?242-ESE-EDB-JetBlue-Database-extension-for-the-Forensic-Browser

Cheers
Paul


   
ReplyQuote
Page 4 / 4
Share: