Notifications
Clear all

Windows 10 Mail App

12 Posts
6 Users
0 Reactions
6,236 Views
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

The book is this one
https://books.google.com/books?id=XJZGDwAAQBAJ

Windows Forensics Cookbook

Oleg Skulkin, Scar de Courcier
Packt Publishing Ltd, 4 ago 2017 - 274 pages

Maximize the power of Windows Forensics to perform highly effective forensic investigations

But it only explains the same folder structure as guillef described and uses FTK Imager, though the process is manual.

It *seems* like the full FTK can actually parse the ESE database
https://www.reddit.com/r/computerforensics/comments/7zho66/windows_10_mail_app/
but cannot rreally say how itr behaves with contents of \3 and \7 folders.

As well the little Nirsoft tool
https://www.nirsoft.net/utils/ese_database_view.html
can actually read the ESE database and export it in several more "digestable" formats, but how it behaves specifically with Windows Mail and its stupid folders is to be seen.

jaclaz


   
ReplyQuote
(@cbryant34)
New Member
Joined: 7 years ago
Posts: 3
 

Hey folks - Cody here from Magnet Forensics. Just wanted to update Jamie's last post to say that Windows 10 mail support was added to AXIOM in version 2.7.0. Let me know if you've got any questions or feedback.

Thanks,
Cody Bryant


   
ReplyQuote
Page 2 / 2
Share: