<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post7846463605179199032..comments</id><updated>2010-11-01T13:25:07.795-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Export files with selected search hits</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/7846463605179199032/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8355193856692900226</id><published>2010-11-01T13:25:07.795-07:00</published><updated>2010-11-01T13:25:07.795-07:00</updated><title type='text'>I know this is an old entry, but revisiting the pr...</title><content type='html'>I know this is an old entry, but revisiting the preservation of metadata when using copy/unerase function. If I tag the search hits and right-click on copy/unerase, all three dates (I&amp;#39;m on Windows 7) are preserved?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/8355193856692900226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/8355193856692900226'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html?showComment=1288643107795#c8355193856692900226' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-305455962'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6279188253355001308</id><published>2010-08-09T11:45:03.158-07:00</published><updated>2010-08-09T11:45:03.158-07:00</updated><title type='text'>Lance,
Have you seen any similar EnScripts that wi...</title><content type='html'>Lance,&lt;br /&gt;Have you seen any similar EnScripts that will do the same for items in the Records tag?  I&amp;#39;m looking for a way to highlight search hits and then flag the entry in Records so these can be exported to msg.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/6279188253355001308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/6279188253355001308'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html?showComment=1281379503158#c6279188253355001308' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-559277503'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5794853479425644663</id><published>2009-10-12T08:10:46.595-07:00</published><updated>2009-10-12T08:10:46.595-07:00</updated><title type='text'>Anonymous,

Thanks for your comments. This EnScrip...</title><content type='html'>Anonymous,&lt;br /&gt;&lt;br /&gt;Thanks for your comments. This EnScript was never designed to preserve the original modified dates, although it can easily be done. EnCase does not preserve them by default when using &amp;quot;copy/unerase&amp;quot; feature either, but that option is available in the EnScript language.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/5794853479425644663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/5794853479425644663'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html?showComment=1255360246595#c5794853479425644663' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1217200401358620155</id><published>2009-10-11T21:06:54.392-07:00</published><updated>2009-10-11T21:06:54.392-07:00</updated><title type='text'>Hi, just wanted to retract my suggestion above as ...</title><content type='html'>Hi, just wanted to retract my suggestion above as I have just realised that the bug is not with your script but with EnCase. So far I have found that version 6.13 and 6.14 does not preserve the Last Modified date when exporting files.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/1217200401358620155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/1217200401358620155'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html?showComment=1255320414392#c1217200401358620155' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1762612464'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1664701302417059554</id><published>2009-10-11T18:00:38.524-07:00</published><updated>2009-10-11T18:00:38.524-07:00</updated><title type='text'>Great script. The only suggestion I have is that t...</title><content type='html'>Great script. The only suggestion I have is that the script maintains the date/time stamps of the file that it exports. I&amp;#39;ve exported a number of files from a case using the script and the Last Modified and File Created date are updated to the data and time the file was exported.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/1664701302417059554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/1664701302417059554'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html?showComment=1255309238524#c1664701302417059554' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1762612464'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2541773574514518546</id><published>2009-04-07T22:08:00.000-07:00</published><updated>2009-04-07T22:08:00.000-07:00</updated><title type='text'>Very nice job Lance (&amp;amp; Scott) - This Enscript ...</title><content type='html'>Very nice job Lance (&amp;amp; Scott) - This Enscript is a great time saver!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/2541773574514518546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/2541773574514518546'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html?showComment=1239167280000#c2541773574514518546' title=''/><author><name>Sandro Süffert - http://suffert.com</name><uri>http://www.blogger.com/profile/16456034990657036324</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_jwummMx97Nw/SWF4TZOAZvI/AAAAAAAAADU/VrNh5FVGEYk/S220/Sandro+Suffert+-+Foto+2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1867614440'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6720374057242022375</id><published>2009-04-07T22:07:00.000-07:00</published><updated>2009-04-07T22:07:00.000-07:00</updated><title type='text'></title><content type='html'>This comment has been removed by the author.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/6720374057242022375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/7846463605179199032/comments/default/6720374057242022375'/><author><name>Sandro Süffert - http://suffert.com</name><uri>http://www.blogger.com/profile/16456034990657036324</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_jwummMx97Nw/SWF4TZOAZvI/AAAAAAAAADU/VrNh5FVGEYk/S220/Sandro+Suffert+-+Foto+2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2009/04/export-files-with-selected-search-hits.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-7846463605179199032' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/7846463605179199032' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.contentRemoved' value='true'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1867614440'/></entry></feed>
