<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post6169632349908200148..comments</id><updated>2011-05-01T21:44:21.702-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Maine State Police - Keyword Search &amp; Export EnScr...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/6169632349908200148/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4215735614126975356</id><published>2010-06-23T22:16:37.576-07:00</published><updated>2010-06-23T22:16:37.576-07:00</updated><title type='text'>Many institutions limit access to their online inf...</title><content type='html'>Many institutions limit access to their online information. Making this information available will be an asset to all.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/4215735614126975356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/4215735614126975356'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html?showComment=1277356597576#c4215735614126975356' title=''/><author><name>research help</name><uri>http://www.researchpaperspot.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-6169632349908200148' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/6169632349908200148' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-789494637'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1378663555522138570</id><published>2010-02-19T16:54:55.501-08:00</published><updated>2010-02-19T16:54:55.501-08:00</updated><title type='text'>Lance,

This EnScript was tremendously useful to m...</title><content type='html'>Lance,&lt;br /&gt;&lt;br /&gt;This EnScript was tremendously useful to me this past week in examining a Limewire/CP case.  Many, many thanks to you &amp;amp; Sgt. Lang!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/1378663555522138570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/1378663555522138570'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html?showComment=1266627295501#c1378663555522138570' title=''/><author><name>T</name><uri>http://www.blogger.com/profile/17125873012471853060</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-6169632349908200148' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/6169632349908200148' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-21037366'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-548012140315475358</id><published>2009-05-24T15:02:58.387-07:00</published><updated>2009-05-24T15:02:58.387-07:00</updated><title type='text'>I don't use EnCase, although I do follow Lance's b...</title><content type='html'>I don't use EnCase, although I do follow Lance's blog, as it's universally helpful.  However, in your case, perhaps formatting or the reinstallation of the OS skewed the cluster boundaries.  Perhaps this is what you meant, but I'd try a byte level grep across the volume.  &lt;br /&gt;&lt;br /&gt;I use X-Ways Forensics to run the greps, directing my searches to begin at every 44032 bytes of free space.  The only problem is that XWF can only search on about 750 of the grep strings at one time.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/548012140315475358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/548012140315475358'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html?showComment=1243202578387#c548012140315475358' title=''/><author><name>Jimmy_Weg</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-6169632349908200148' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/6169632349908200148' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-980106048'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2841150591996541821</id><published>2009-05-18T08:03:00.000-07:00</published><updated>2009-05-18T08:03:00.000-07:00</updated><title type='text'>I attempted to use this EnScript on a P2P case whe...</title><content type='html'>I attempted to use this EnScript on a P2P case where the suspect had approximately 120 known CP files during the controlled download stage, but had re-installed Windows XP the week prior to my hitting the house. I have his admission, I'm just lacking actual content at this point. I can see plenty of remnants in drive free space on the 100GB drive. I've tried running this EnScript twice without anything getting bookmarked. &lt;br /&gt;I'm going to try just running the GREP keywords straight to see if that might be the issue.&lt;br /&gt;Is the older movie parser EnScript demonstrated in the video still available to try?&lt;br /&gt;Thanks, &lt;br /&gt;Jeff Datzman&lt;br /&gt;Vacaville PD&lt;br /&gt;707-469-4741&lt;br /&gt;JDatzman@cityofvacaville.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/2841150591996541821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/6169632349908200148/comments/default/2841150591996541821'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html?showComment=1242658980000#c2841150591996541821' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/05372586376534162228</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/maine-state-police-keyword-search.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-6169632349908200148' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/6169632349908200148' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1981671489'/></entry></feed>
