Wednesday, April 1, 2015

EnCase v7 EnScript to report on file types by extension

Several years ago I wrote a quick EnScript to produce a quick report of how many files with each extension were found in the case. That EnScript was originally written for EnCase v6 and not compiled so it could be used as a learning exercise.

I recently had a request to update this EnScript for EnCase v7 and to add the byte count for each extension.

The output goes to a TSV file in the case export folder and to the console:

Extension: txt    Count: 9    Size:6787
Extension: csv    Count: 16    Size:1357315
Extension: dat    Count: 9    Size:2129920
Extension: sqlite    Count: 4    Size:11272192
Extension: log    Count: 35    Size:4739968
Extension: evtx    Count: 9    Size:3772416
Extension: fls    Count: 1    Size:0
Extension: mft    Count: 1    Size:52166656
Extension: raw    Count: 1    Size:1073741824
Extension: pf    Count: 129    Size:7745128
Extension: db    Count: 7    Size:4099460
Extension: bin    Count: 1    Size:508
Extension: fx    Count: 5    Size:9060831

Download EnCase v7 EnScript Here


2 comments:

Sean Thursday, 10 December, 2015  

Hi there, I get an error on running this in Encase v7.05
"NOPROXY" is an unknown identifier".

Lance Mueller Thursday, 10 December, 2015  

You should update your version of EnCase.

Post a Comment

Computer Forensics, Malware Analysis & Digital Investigations

Random Articles