<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post2129108010099059666..comments</id><updated>2011-05-23T00:53:22.879-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: EnScript to Export files by extension</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/2129108010099059666/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-314258699864315154</id><published>2011-05-23T00:53:22.879-07:00</published><updated>2011-05-23T00:53:22.879-07:00</updated><title type='text'>Hello Lance,
This is a very handy tool. We use it ...</title><content type='html'>Hello Lance,&lt;br /&gt;This is a very handy tool. We use it here in the Netherlands(Hague Police Force) to quickly extract files, we then put in a tool called Forensic Websearch. This tool gives a tactical investigator the possibility to search in digital evidence from a location outside our office. &lt;br /&gt;Is it possible that we (like the collegue above) can obtain the source code from you, so we can make some (minor) modifications to suit our purposes?&lt;br /&gt;If you don&amp;#39;t want to provide the code, we fully understand that, and we appreciate all your efforts for making the live of a digital investigator a little easier....&lt;br /&gt;With regards,&lt;br /&gt;Frits van Beukering&lt;br /&gt;frits@digitale-expertise.nl</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/314258699864315154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/314258699864315154'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html?showComment=1306137202879#c314258699864315154' title=''/><author><name>LinuxAdventures</name><uri>http://www.blogger.com/profile/01067800375690650214</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-2129108010099059666' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/2129108010099059666' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1953632381'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-938756960473073272</id><published>2010-02-18T07:32:43.469-08:00</published><updated>2010-02-18T07:32:43.469-08:00</updated><title type='text'>Hi Lance, any possibility of getting the source co...</title><content type='html'>Hi Lance, any possibility of getting the source code for the EnScript to Export files by extensions? I&amp;#39;d like to make some specific modifications to my version of your code, but cannot do that without the actual EnScript.&lt;br /&gt;&lt;br /&gt;If you do not feel comfortable in provide the source code, I will understand completely.&lt;br /&gt;&lt;br /&gt;Thank you for considering my request.&lt;br /&gt;HD</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/938756960473073272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/938756960473073272'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html?showComment=1266507163469#c938756960473073272' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-2129108010099059666' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/2129108010099059666' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-183567694'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5785937119116218917</id><published>2009-07-10T00:17:44.469-07:00</published><updated>2009-07-10T00:17:44.469-07:00</updated><title type='text'>i send the last post above. my e-mail:kocamaz.cane...</title><content type='html'>i send the last post above. my e-mail:kocamaz.caner@gmail.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/5785937119116218917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/5785937119116218917'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html?showComment=1247210264469#c5785937119116218917' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-2129108010099059666' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/2129108010099059666' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-678897104'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2437299644970067687</id><published>2009-07-08T06:42:00.541-07:00</published><updated>2009-07-08T06:42:00.541-07:00</updated><title type='text'>Hi,
i am examining a case, includes 40 harddisks i...</title><content type='html'>Hi,&lt;br /&gt;i am examining a case, includes 40 harddisks image files. i added all image files to one case. i need a script which do those followings&lt;br /&gt;1-it will create a folder(folder name=image file name, exclude E01 extension) for every image files under Export Folder.&lt;br /&gt;2-it will create subfolders( a some file extension named folder ) every created folders.&lt;br /&gt;for example&lt;br /&gt;&lt;br /&gt;folder name:image1&lt;br /&gt;subfolders: doc, xls,avi,mpg&lt;br /&gt;&lt;br /&gt;it will do same again every image files (image2,...image40).&lt;br /&gt;&lt;br /&gt;3-it will copy doc extension files to doc subfolder, xls files to xls folder etc.&lt;br /&gt;&lt;br /&gt;i tried do this but i couldnt solved completely. i edit a Encase built-in script below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;typedef String[] files;&lt;br /&gt;class MainClass&lt;br /&gt;{&lt;br /&gt;void Main(CaseClass c)&lt;br /&gt;{&lt;br /&gt;EntryClass e;&lt;br /&gt;files f{&amp;quot;doc&amp;quot;,&amp;quot;xls&amp;quot;,&amp;quot;pdf&amp;quot;,&amp;quot;txt&amp;quot;,&amp;quot;rtf&amp;quot;};&lt;br /&gt;String outputPath;&lt;br /&gt;LocalFileClass ofolder();&lt;br /&gt;&lt;br /&gt;forall(DeviceClass dev in c.DeviceRoot())&lt;br /&gt;{&lt;br /&gt;Console.Write(dev.Name()+&amp;quot;\n&amp;quot;);&lt;br /&gt;outputPath=c.ExportFolder()+&amp;quot;\\&amp;quot;+dev.Name();&lt;br /&gt;//Console.Write(outputPath.GetFilePath()+&amp;quot;\n&amp;quot;);&lt;br /&gt;&lt;br /&gt;for(int i=0;i(less-than)f.Count();i++)&lt;br /&gt;{&lt;br /&gt;if (LocalMachine.PathExists(outputPath.GetFilePath()+ &amp;quot;\\&amp;quot;+dev.Name()+&amp;quot;\\&amp;quot;+f[i]) == false)&lt;br /&gt;{&lt;br /&gt;LocalMachine.CreateFolder(outputPath.GetFilePath() +&amp;quot;\\&amp;quot;+dev.Name()+&amp;quot;\\&amp;quot;+f[i], ConnectionClass::CREATEFOLDERALL);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;e=dev.GetRootEntry();&lt;br /&gt;//Console.Write(e.Name()+&amp;quot;\n&amp;quot;);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;}//MainClass&lt;br /&gt;&lt;br /&gt;** i couldnt copy files every subfolders. i am waiting your helps. Thanx.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/2437299644970067687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/2437299644970067687'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html?showComment=1247060520541#c2437299644970067687' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-2129108010099059666' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/2129108010099059666' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-678897104'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6386882905229320089</id><published>2009-06-30T01:39:10.020-07:00</published><updated>2009-06-30T01:39:10.020-07:00</updated><title type='text'>Hey Lance,

I find this to be a mighty useful scri...</title><content type='html'>Hey Lance,&lt;br /&gt;&lt;br /&gt;I find this to be a mighty useful script. In a typical e-discovery case what would be your methodology. You use this instead of a custom filter? The other questions would be:&lt;br /&gt;1. Does it export the files with bad signatures or overwritten? (they still have the right extensions)&lt;br /&gt;2. What is your approach towards carved files? You first run this script and only then (if necessary, requested) set-up the carving for specific filetypes and export them as search hits into a separate folder?&lt;br /&gt;&lt;br /&gt;Thank you again for the script - I will check it as soon as I can.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/6386882905229320089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/6386882905229320089'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html?showComment=1246351150020#c6386882905229320089' title=''/><author><name>V</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-2129108010099059666' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/2129108010099059666' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1566595379'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1048270289883573647</id><published>2009-06-29T09:03:42.624-07:00</published><updated>2009-06-29T09:03:42.624-07:00</updated><title type='text'>Hey Lance, hope all is well....!  Cool idea, thank...</title><content type='html'>Hey Lance, hope all is well....!  Cool idea, thanks for putting it together, and as always, thanks for sharing.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/1048270289883573647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/2129108010099059666/comments/default/1048270289883573647'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html?showComment=1246291422624#c1048270289883573647' title=''/><author><name>Matt Albee</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/06/enscript-to-export-files-by-extension.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-2129108010099059666' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/2129108010099059666' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1122566123'/></entry></feed>
