Electronic Evidence Examiner
Total Page:16
File Type:pdf, Size:1020Kb
2 Table of Contents About Electronic Evidence Examiner How To .......................................................................12 How to Work with Cases .........................................................................................................13 How to Create New Case .......................................................................................................13 How to Enable Automatic Case Naming .................................................................................14 How to Define Case Name During Automatic Case Creation .................................................14 How to Open Existing Case....................................................................................................15 How to Save Case to Archive .................................................................................................16 How to Change Default Case Location ...................................................................................16 How to Add Data to Case ........................................................................................................17 How to Add Evidence .............................................................................................................18 How to Acquire Devices .........................................................................................................20 How to Import Mobile Data .....................................................................................................21 How to Import Cloud Data ......................................................................................................22 How to Import Office 365 Data ...............................................................................................23 How to Prepare Environment for Importing Office 365 Data ............................................... 23 How to Import Office 365 Data ........................................................................................... 31 How to Investigate Different Types of Evidence ...................................................................32 How to Investigate Mailstorages .............................................................................................32 How to Investigate Different Types of Mailstorages ............................................................ 33 How to Autodetect Mailstorage Format ................................................................................. 33 How to Investigate America On-line (AOL) Mailstorage....................................................... 35 How to Investigate Microsoft Exchange Mailstorage ............................................................ 36 How to Investigate GroupWise Mailstorage .......................................................................... 40 How to Investigate Lotus Notes Mailstorage ......................................................................... 42 How to Investigate Microsoft Outlook Mailstorage ............................................................... 46 How to Investigate The Bat! Mailstorage ............................................................................... 48 How to Investigate Thunderbird Mailstorage ......................................................................... 51 How to Investigate Outlook Express Mailstorage ................................................................. 52 How to Investigate Eudora Mailstorage ................................................................................. 54 How to Investigate E-mail Files .............................................................................................. 56 3 How to Investigate E-mail Examiner Archive ........................................................................ 57 How to Investigate Google Takeout Storage ........................................................................ 58 How to Investigate Windows Mail Database ......................................................................... 60 How to Investigate Maildir Database ..................................................................................... 61 How to Investigate Windows 10 Mail database .................................................................... 62 How to Investigate Mailstorage Stored within Added File System Evidence ..................... 64 How to Investigate E-mails Stored in tar.gz Archives ........................................................... 64 How to View Mailstorage Evidence .................................................................................... 65 How to View Messages in Different Formats ........................................................................ 65 How to View Attachments ....................................................................................................... 66 How to View Attachments that Can Be Opened as Embedded Evidence .......................... 68 How to Detect Attachment File Types ................................................................................... 68 How to Perform Searches in Mailstorage Evidence ............................................................ 69 How to Search in Mailstorages ............................................................................................... 69 How to Search in Message Attachments............................................................................... 70 How to Search in Mailstorage by Attachment Type.............................................................. 72 How to Search for Data in Message Body Only ................................................................... 73 How to Find Emails with Particular Senders or Particular Receivers.................................. 74 How to Search in Deleted Email Messages .......................................................................... 76 How to Search in Email Messages Sent on a Specific Date ............................................... 77 How to Search for Email Addresses Sent in Message Bodies ............................................ 79 How to Search for Text Data .................................................................................................. 80 How to Export Mailstorage Data ......................................................................................... 82 How to Export the Mailstorage to Another Format ............................................................... 82 How to Export an Attachment ................................................................................................. 83 How to Export All Attachments ............................................................................................... 84 How to Create Attachments List ............................................................................................. 85 How to Print Messages ...................................................................................................... 86 How to Investigate Chat Databases .......................................................................................87 How to Investigate Different Types of Chat Databases ...................................................... 87 How to Autodetect Chat Database Format............................................................................ 87 How to Investigate Yahoo! Chat Databases ......................................................................... 88 4 How to Investigate Skype Chat Databases ........................................................................... 89 How to Investigate ICQ Chat Databases ............................................................................... 91 How to Investigate Miranda Chat Databases ........................................................................ 93 How to Investigate Hello Chat Databases ............................................................................. 94 How to Investigate Trillian Chat Databases .......................................................................... 95 How to Investigate MSN and Windows Live Chat Databases ............................................. 96 How to Investigate Chat Database Stored Within Added File System Evidence ............... 97 How to View Chat Database Evidence ............................................................................... 98 How to View Chat History ....................................................................................................... 98 How to View Skype File Transfer History .............................................................................. 99 How to Perform Searches in Chat Database Evidence .................................................... 100 How to Search in Chat Databases ....................................................................................... 100 How to Search for Messages from Several Combined Screennames .............................. 101 How to Search for Messages that Were Sent at a Specific Time ..................................... 102 How to Investigate Internet Browser data ............................................................................. 103 How to View History and Temporary Internet Files Created by Internet Explorer ............. 103 How to View Mozilla Firefox History Data ......................................................................... 104 How to View Google Chrome Data................................................................................... 106 How to View Google Chrome Keywords .........................................................................