by Arman Gungor
When mailboxes are forensically preserved for eDiscovery or digital forensic investigations, their contents are almost always searched and filtered. Filtering emails helps overcome time, scope and cost constraints and alleviates privacy concerns.
There are two main ways of filtering emails—before and after the forensic acquisition. Each method has its pros and cons, which we will discuss here.