<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post1858768570342548695..comments</id><updated>2010-01-12T14:06:23.610-08:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: EnScript to create LEF with files based on extensi...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/1858768570342548695/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1110674076973842057</id><published>2010-01-12T14:06:23.610-08:00</published><updated>2010-01-12T14:06:23.610-08:00</updated><title type='text'>I downloaded the most recent version of the script...</title><content type='html'>I downloaded the most recent version of the script for use but am getting the following error: &amp;quot;SOURCELOGICAL&amp;quot; is an unknown identifier&amp;quot;&lt;br /&gt;&lt;br /&gt;Any thoughts?  Thanks for all your efforts in making this available to the community.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/1110674076973842057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/1110674076973842057'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1263333983610#c1110674076973842057' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1541144554'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6219523055732305712</id><published>2009-12-03T07:14:43.998-08:00</published><updated>2009-12-03T07:14:43.998-08:00</updated><title type='text'>None that I am aware of, but you could certainly w...</title><content type='html'>None that I am aware of, but you could certainly write a condition to display the files based on your GREP and then blue check them and create your own LEF.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/6219523055732305712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/6219523055732305712'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1259853283998#c6219523055732305712' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9093801886869401972</id><published>2009-12-03T07:12:01.211-08:00</published><updated>2009-12-03T07:12:01.211-08:00</updated><title type='text'>ThNX for the reply, do you know if there&amp;#39;s a s...</title><content type='html'>ThNX for the reply, do you know if there&amp;#39;s a similar kind of script which does use GREP?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/9093801886869401972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/9093801886869401972'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1259853121211#c9093801886869401972' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-824826470'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5584323741286829189</id><published>2009-12-03T03:56:16.130-08:00</published><updated>2009-12-03T03:56:16.130-08:00</updated><title type='text'>Only based on the extension text, no GREP.</title><content type='html'>Only based on the extension text, no GREP.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/5584323741286829189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/5584323741286829189'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1259841376130#c5584323741286829189' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9170360856719340835</id><published>2009-12-03T03:49:23.840-08:00</published><updated>2009-12-03T03:49:23.840-08:00</updated><title type='text'>does this script also uses the GREP-option or just...</title><content type='html'>does this script also uses the GREP-option or just the extensions from the file names?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/9170360856719340835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/9170360856719340835'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1259840963840#c9170360856719340835' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1956098688'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1468725198688038719</id><published>2009-11-19T01:51:36.477-08:00</published><updated>2009-11-19T01:51:36.477-08:00</updated><title type='text'>I have just uploaded the latest version, downloade...</title><content type='html'>I have just uploaded the latest version, downloaded it and tested it. The current download should be exactly as described.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/1468725198688038719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/1468725198688038719'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1258624296477#c1468725198688038719' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3785424713295619283</id><published>2009-11-18T14:02:32.845-08:00</published><updated>2009-11-18T14:02:32.845-08:00</updated><title type='text'>I can confirm also that the current script running...</title><content type='html'>I can confirm also that the current script running under 6.13 in WinXP does not contain the check boxes mentioned.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/3785424713295619283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/3785424713295619283'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1258581752845#c3785424713295619283' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1780974889'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-315714615102129695</id><published>2009-11-12T20:30:11.001-08:00</published><updated>2009-11-12T20:30:11.001-08:00</updated><title type='text'>Not sure what you mean</title><content type='html'>Not sure what you mean</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/315714615102129695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/315714615102129695'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1258086611001#c315714615102129695' title=''/><author><name>Lance Mueller</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1698696934'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7316419250652767025</id><published>2009-11-12T13:21:53.333-08:00</published><updated>2009-11-12T13:21:53.333-08:00</updated><title type='text'>I downloaded it but not sure if its right. The win...</title><content type='html'>I downloaded it but not sure if its right. The window doesn&amp;#39;t have the 2 checkboxes below the extensions field.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/7316419250652767025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1858768570342548695/comments/default/7316419250652767025'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html?showComment=1258060913333#c7316419250652767025' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/10/enscript-to-create-lef-with-files-based.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1858768570342548695' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1858768570342548695' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-670881525'/></entry></feed>
