<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post449508559546845684..comments</id><updated>2010-07-08T12:58:32.819-07:00</updated><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: If you could have any EnScript or filter,  what wo...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/449508559546845684/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default?start-index=26&amp;max-results=25'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>27</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-213051408518856481</id><published>2010-07-08T12:58:32.680-07:00</published><updated>2010-07-08T12:58:32.680-07:00</updated><title type='text'>I have seen an Enscript like this once, but I do n...</title><content type='html'>I have seen an Enscript like this once, but I do not have it.&lt;br /&gt;&lt;br /&gt;This enscript goes through the computer and finds all prefetch files and pulls the data out of them into a spreadsheet.  The data that it pulls shows the name of the file, its location, and the previous times that it was ran.  This script would be of great use in my investigations.  Any help would be appreciated.&lt;br /&gt;&lt;br /&gt;Brannon Raines&lt;br /&gt;brannon.raines@wellsfargo.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/213051408518856481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/213051408518856481'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1278619112680#c213051408518856481' title=''/><author><name>Brannon Raines</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3621458995139072402</id><published>2010-06-16T20:24:16.150-07:00</published><updated>2010-06-16T20:24:16.150-07:00</updated><title type='text'>I would like to see an. EnScript that parses gigat...</title><content type='html'>I would like to see an. EnScript that parses gigatribe chat files into a readable format.&lt;br /&gt;&lt;br /&gt;Tom Bell&lt;br /&gt;KYOAG&lt;br /&gt;tom.bell@ag.ky.gov</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/3621458995139072402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/3621458995139072402'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1276745056150#c3621458995139072402' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8094788899430278873</id><published>2009-04-22T12:21:00.000-07:00</published><updated>2009-04-22T12:21:00.000-07:00</updated><title type='text'>AccessData's registry viewer product has a near fe...</title><content type='html'>AccessData's registry viewer product has a near feature called Auto RSR.  This allows one to generate a registry report and include whichever keys desired.  Something like this would make a nice Enscript.  Especially if it gave the option to parse restore points.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/8094788899430278873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/8094788899430278873'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1240428060000#c8094788899430278873' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7365953455567460337</id><published>2009-04-10T12:29:00.000-07:00</published><updated>2009-04-10T12:29:00.000-07:00</updated><title type='text'>I would like an EnScript that will parse DHCP hist...</title><content type='html'>I would like an EnScript that will parse DHCP history out of the registry restore points.  i.e. I would like it to find, mount, and parse each restore point on the hard drive and list the following:&lt;BR/&gt;&lt;BR/&gt;Assigned DHCP assigned IP Address&lt;BR/&gt;IP address Lease Start date/time&lt;BR/&gt;IP address Lease End date/time&lt;BR/&gt;&lt;BR/&gt;It would be nice if it presented it in an easy to read timeline format.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/7365953455567460337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/7365953455567460337'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1239391740000#c7365953455567460337' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8219817619439456781</id><published>2009-03-23T09:45:00.000-07:00</published><updated>2009-03-23T09:45:00.000-07:00</updated><title type='text'>I'm looking for an enscript that will export all s...</title><content type='html'>I'm looking for an enscript that will export all selected files and rename them to either include the file name and/or the md5 with the correct extension appended to the end. Ideas?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/8219817619439456781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/8219817619439456781'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1237826700000#c8219817619439456781' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5571396755439639754</id><published>2009-03-23T06:54:00.000-07:00</published><updated>2009-03-23T06:54:00.000-07:00</updated><title type='text'>Carlos,You might want to take a look at P2P Marsha...</title><content type='html'>Carlos,&lt;BR/&gt;You might want to take a look at P2P Marshal for P2P stuff, funded by the NIJ.&lt;BR/&gt;http://p2pmarshal.atc-nycorp.com/&lt;BR/&gt;Though i should warn you its not perfect in my experience (others seem to like it - thought its missed stuff for me on partial installations).&lt;BR/&gt;Rich</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/5571396755439639754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/5571396755439639754'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1237816440000#c5571396755439639754' title=''/><author><name>Rich2005</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6698918101300338620</id><published>2009-02-26T15:28:00.000-08:00</published><updated>2009-02-26T15:28:00.000-08:00</updated><title type='text'>Hi I am with DHS-Immigration and Customs Enforceme...</title><content type='html'>Hi &lt;BR/&gt;I am with DHS-Immigration and Customs Enforcement (ICE), Computer Forensic Lab at Puerto Rico.&lt;BR/&gt;&lt;BR/&gt;What I like to see is and Enscrip to check Local User Profile for all other Chat Clients (Yahoo, MSN, etc.)Chat logs&lt;BR/&gt;&lt;BR/&gt;P2P download Logs (Bittorrent, Limewire etc.)&lt;BR/&gt;&lt;BR/&gt;Somehting that makes a quick report of their file trading and activity for tracking Child Porn.&lt;BR/&gt;&lt;BR/&gt;carlos.a.negron@dhs.gov</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6698918101300338620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6698918101300338620'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1235690880000#c6698918101300338620' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2394698163339555713</id><published>2009-02-25T03:29:00.000-08:00</published><updated>2009-02-25T03:29:00.000-08:00</updated><title type='text'>Hi Mueller,Can a Enscript be written which can par...</title><content type='html'>Hi Mueller,&lt;BR/&gt;&lt;BR/&gt;Can a Enscript be written which can parse the live memory for gtalk chats and store the results in bookmark. I want gtalk only as they are not stored on the local machines.&lt;BR/&gt;&lt;BR/&gt;Kush Wadhwa&lt;BR/&gt;(kushwadhwa@gmail.com)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/2394698163339555713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/2394698163339555713'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1235561340000#c2394698163339555713' title=''/><author><name>Kush Wadhwa</name><uri>http://www.blogger.com/profile/10761246058955112644</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7422386154018135259</id><published>2009-01-30T16:27:00.000-08:00</published><updated>2009-01-30T16:27:00.000-08:00</updated><title type='text'>I'd love an EnScript that would convert all the se...</title><content type='html'>I'd love an EnScript that would convert all the selected items to PDF with Bates numbers. Yes, I can do this by hand. Yes, it is better done by other tools, but I'm ending up doing "ediscovery in the field" more often than I'd like.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/7422386154018135259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/7422386154018135259'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1233361620000#c7422386154018135259' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4945975333494285530</id><published>2008-11-11T13:59:00.000-08:00</published><updated>2008-11-11T13:59:00.000-08:00</updated><title type='text'>How about a script that would linearly copy out un...</title><content type='html'>How about a script that would linearly copy out unallocated space, unused disk area, pagefile.sys,  hiberfil.sys and start the hashing process one after the other as not to kill the machine?  &lt;BR/&gt;Thanks a lot for this blog, it is very useful!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/4945975333494285530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/4945975333494285530'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1226440740000#c4945975333494285530' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6135078296483995511</id><published>2008-11-10T11:37:00.000-08:00</published><updated>2008-11-10T11:37:00.000-08:00</updated><title type='text'>Lance, sorry to butt in without a suggestion for a...</title><content type='html'>Lance, sorry to butt in without a suggestion for a script but I was reading the suggestions when I saw that "a" was asking for a script which " parses out and bookmarks the ramnents of (live)messenger out selected files (unallocated/pagefile/hyberfil)". If this is referring to MSNP remnants of conversation my colleague has already done this - http://computerforensics.parsonage.co.uk/downloads/MSNTextFragmentsFinder.zip&lt;BR/&gt;H</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6135078296483995511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6135078296483995511'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1226345820000#c6135078296483995511' title=''/><author><name>harryparsonage</name><uri>http://www.blogger.com/profile/11774876007771263349</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3339964893299973593</id><published>2008-11-08T05:57:00.000-08:00</published><updated>2008-11-08T05:57:00.000-08:00</updated><title type='text'>How about being able to do anything from Enscript ...</title><content type='html'>How about being able to do anything from Enscript that you can do from the GUI.  Ever hear of automation?  You can only recover folders when you add a device in v6.  However, last I checked, you can't programmatically add a multi-file dd style image.  In all honesty, though, I have stayed away from v6 because I get "Out of Memory" errors when I approach a large number of "files".  The same case doesn't give me problems in v5 but alas, v5 is even worse with automation, can't perform a sig and hash search.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/3339964893299973593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/3339964893299973593'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1226152620000#c3339964893299973593' title=''/><author><name>Greg Kelley</name><uri>http://www.blogger.com/profile/11087813718826491542</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6476356364302186511</id><published>2008-10-31T13:10:00.000-07:00</published><updated>2008-10-31T13:10:00.000-07:00</updated><title type='text'>Lance...How about an EnScript that will rip throug...</title><content type='html'>Lance...&lt;BR/&gt;&lt;BR/&gt;How about an EnScript that will rip through the registry based on the white paper and spreadsheet that I sent you...&lt;BR/&gt;&lt;BR/&gt;Dan P.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6476356364302186511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6476356364302186511'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1225483800000#c6476356364302186511' title=''/><author><name>Dan</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9151185303008357804</id><published>2008-10-29T21:11:00.000-07:00</published><updated>2008-10-29T21:11:00.000-07:00</updated><title type='text'>How about a "First Run" script which combines come...</title><content type='html'>How about a "First Run" script which combines come of the basics and outputs into a csv format with date being the first column and time the second column.  For example the basics could include:&lt;BR/&gt;-USB Information &lt;BR/&gt;-Mounted Drives&lt;BR/&gt;-Parse Link Files&lt;BR/&gt;-MAC of all files between dates&lt;BR/&gt;-Event logs(Limited to default locations)&lt;BR/&gt;-MRU's from Registry&lt;BR/&gt;-WEP&lt;BR/&gt;-Printers&lt;BR/&gt;-Prefetch&lt;BR/&gt;-Internet History (Limited to default locations)&lt;BR/&gt;etc&lt;BR/&gt;&lt;BR/&gt;Although some of these scripts currently exist they do not output in a standardized format.  The "First Run" script would mean a first responder could get an instant report on scene of the basics immediately after imaging has been completed.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/9151185303008357804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/9151185303008357804'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1225339860000#c9151185303008357804' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6782000372659541608</id><published>2008-10-29T07:28:00.000-07:00</published><updated>2008-10-29T07:28:00.000-07:00</updated><title type='text'>I'd like and EnScript that leveraged Volatility (a...</title><content type='html'>I'd like and EnScript that leveraged Volatility (a.k.a. the greatest thing since sliced bread) against a mem dump file.  The GUI popup would allow the user to 'check box' the various Volatility command line options.  The output would be a CSV file and would appropriately associate the output of the selected options to the correct process (PID).  The idea is that it creates an easy read on a per process level.  Volatility provides a lot of disparate info on each process.  This EnScript would essentially format the Volatility output in a "makes sense" manner.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6782000372659541608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6782000372659541608'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1225290480000#c6782000372659541608' title=''/><author><name>jobel</name><uri>http://www.blogger.com/profile/06794676714562793474</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4491939229193018816</id><published>2008-10-28T07:55:00.000-07:00</published><updated>2008-10-28T07:55:00.000-07:00</updated><title type='text'>An easy, but always requested one:Dialog-"Where", ...</title><content type='html'>An easy, but always requested one:&lt;BR/&gt;Dialog-"Where", and "Named"&lt;BR/&gt;Output-Case Folder Structure!&lt;BR/&gt;(with an option for For/eDisc/Inv/etc)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/4491939229193018816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/4491939229193018816'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1225205700000#c4491939229193018816' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4624107768139220543</id><published>2008-10-27T07:44:00.000-07:00</published><updated>2008-10-27T07:44:00.000-07:00</updated><title type='text'>I would like an enscript that creates a timeline o...</title><content type='html'>I would like an enscript that creates a timeline of every entry in the case, I have found the timeline functionality of encase unstable and awkward to work with. By all entries I mean MAC times, Reg c times, Internet history access/update times, and other user defined times (such as network logs, etc.). This way, an investigator can create a timeline of all of the events on the system and use it to rebuild the history. He will be able to integrate the network/system logs to correlate these events.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/4624107768139220543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/4624107768139220543'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1225118640000#c4624107768139220543' title=''/><author><name>aliarasteh</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9001613132834492833</id><published>2008-10-27T07:36:00.000-07:00</published><updated>2008-10-27T07:36:00.000-07:00</updated><title type='text'>I would like to see an enscript that diffs active ...</title><content type='html'>I would like to see an enscript that diffs active registry files and system restore points registry files and exports only the changes</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/9001613132834492833'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/9001613132834492833'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1225118160000#c9001613132834492833' title=''/><author><name>SAL</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-948382981805291878</id><published>2008-10-24T08:51:00.000-07:00</published><updated>2008-10-24T08:51:00.000-07:00</updated><title type='text'>Hans,That's a good idea, but it can already be eas...</title><content type='html'>Hans,&lt;BR/&gt;&lt;BR/&gt;That's a good idea, but it can already be easily accomplished without an EnScript in about 20 seconds using a condition. &lt;BR/&gt;&lt;BR/&gt;Just take your list of paths/files that you want to know about and create a condition that says "if full path contains" and then paste your list of paths, then run. The only files that will be shown to you are those that match your path criteria.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/948382981805291878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/948382981805291878'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224863460000#c948382981805291878' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08464705455452496935'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6391562695203138688</id><published>2008-10-24T08:33:00.000-07:00</published><updated>2008-10-24T08:33:00.000-07:00</updated><title type='text'>Interesting things enscriptI would like a solution...</title><content type='html'>&lt;B&gt;Interesting things enscript&lt;/B&gt;&lt;BR/&gt;&lt;BR/&gt;I would like a solution for a quick scan of interesting things that possible resides on a Windows disk.&lt;BR/&gt;Purpose is to find out which interesting things resides in the data. Its purpose is not to export or carve data. Just knowing that interesting things are present is enough to set up a plan to investigate that data.&lt;BR/&gt;&lt;BR/&gt;The script should look for particular file names/file path/extensions&lt;BR/&gt;&lt;BR/&gt;The script should pick the particular names, etc. from a reference file. Every investigator should be able to  edit the reference file, so he/she can put in names/path/etc. he/she wishes to be searched for. I think this will be a great solution for investigators all over the World. In many cases particular software, software names and (path) names are language/country dependent.&lt;BR/&gt;&lt;BR/&gt;A further advantage is, that the investigator self decides what he/she is looking for. &lt;BR/&gt;&lt;A HREF="http://www.hansheins.nl/forensics/Enscipt-wishes/Enscript_wishes.pdf" REL="nofollow"&gt;&lt;BR/&gt;Further Info&lt;/A&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6391562695203138688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/6391562695203138688'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224862380000#c6391562695203138688' title=''/><author><name>hans</name><uri>http://www.blogger.com/profile/10133092635400237609</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3754538544315150981</id><published>2008-10-23T23:53:00.000-07:00</published><updated>2008-10-23T23:53:00.000-07:00</updated><title type='text'>I would like to have an Enscript that parses out a...</title><content type='html'>I would like to have an Enscript that parses out and bookmarks the ramnents of (live)messenger out selected files (unallocated/pagefile/hyberfil)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/3754538544315150981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/3754538544315150981'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224831180000#c3754538544315150981' title=''/><author><name>A</name><uri>http://www.blogger.com/profile/09695445057660117747</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2206997538044808247</id><published>2008-10-23T10:25:00.000-07:00</published><updated>2008-10-23T10:25:00.000-07:00</updated><title type='text'>I would like to have an Enscript witch can map/par...</title><content type='html'>I would like to have an Enscript witch can map/parse the Vista-Filenames/paths to the Thumbscache entries.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/2206997538044808247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/2206997538044808247'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224782700000#c2206997538044808247' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8480679981756213210</id><published>2008-10-22T19:33:00.000-07:00</published><updated>2008-10-22T19:33:00.000-07:00</updated><title type='text'>Some interesting ideas so far. Albee, keep dreamin...</title><content type='html'>Some interesting ideas so far. Albee, keep dreaming! ;)&lt;BR/&gt;&lt;BR/&gt;Paul Bobby, what kind of information are you interested in from the DCOM database?&lt;BR/&gt;&lt;BR/&gt;Skype is a good idea.&lt;BR/&gt;&lt;BR/&gt;Larry, I think I can modify the script I have posted here to do what you want.&lt;BR/&gt;&lt;BR/&gt;Keep the ideas coming!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/8480679981756213210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/8480679981756213210'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224729180000#c8480679981756213210' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='08464705455452496935'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7591107808896623634</id><published>2008-10-22T16:09:00.000-07:00</published><updated>2008-10-22T16:09:00.000-07:00</updated><title type='text'>Producing forensic evidence from the DCOM database...</title><content type='html'>Producing forensic evidence from the DCOM database files on a deadbox hard drive.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/7591107808896623634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/7591107808896623634'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224716940000#c7591107808896623634' title=''/><author><name>Paul Bobby</name><uri>http://www.blogger.com/profile/10685628856061244051</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1088959820348075829</id><published>2008-10-22T15:43:00.000-07:00</published><updated>2008-10-22T15:43:00.000-07:00</updated><title type='text'>I would love to have an Enscript that can parse th...</title><content type='html'>I would love to have an Enscript that can parse the meta data out of office files in bulk (i.e. All checked files) and would write them to a tab delimited text file I can import and post process in a database.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/1088959820348075829'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/449508559546845684/comments/default/1088959820348075829'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html?showComment=1224715380000#c1088959820348075829' title=''/><author><name>Larry E. Daniel</name><uri>http://www.blogger.com/profile/09201368667213383998</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/10/if-you-could-have-any-enscript-or.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-449508559546845684' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/449508559546845684' type='text/html'/></entry></feed>