|
|
|
| |
| |
Datei-Container
Überblick
|
Datei-Container sind logische Images, die nur
ausgewählte Dateien enthalten. Sie werden entweder für die
elektronische Beweismittelsicherung verwendet als Ersatz für
konventionelle forensische Images (in Fällen, in denen nur einie
Dateien benötigt werden und ein kompletten sektorweise erstelles
Image stark übertrieben wäre) oder zum Austausch ausgewählter
Dateien mit anderen Ermittlern, Staatsanwälten, Rechtsanwälten, die
Gegenseite usw. Evidence file containers can be created by
X-Ways Forensics and
X-Ways Investigator. They are designed to
preserve as much metadata as possible, see below.
Vergleich mit sog.
Minimalsicherungen.
Containers are initially raw
images with a special file system (XWFS2), and they can be converted
to .e01 evidence file format. The information on this page is about the new container
format used by v16.3 and later. It is as universal as it gets and can
be understood by 3rd party forensic tools with in depth file system
support out of the box or with little
additional effort.
|
|
Basis-Metadaten |
Liste:
-
filename
-
path
-
logical file size
-
valid data length
-
ordinary Windows world
attributes
-
existing or deleted
-
creation date
-
modification date
-
last access date
-
last record update date
-
hard link count
-
examiner classifications (report table
associations)
-
examiner comments
Basis-Metadaten und Datei-Inhalte in Datei-Containern
werden verstanden von:
-
EnCase 5
-
EnCase 6
-
EnCase 7
-
MountImage Pro 4 (Image erst hinzufügen, dann
Dateisystem mounten)
-
WinHex 12.5 und neuer, mit Specialist-Lizenz oder
höher
-
X-Ways Forensics 12.5 und neuer
-
X-Ways Investigator, alle Versionen
-
…
|
|
Erweiterte Metadaten |
Liste:
-
advanced deletion status
(existing, previously existing, moved/renamed, partially
overwritten)
-
original file system file ID
-
original file system data
structure offset
-
deletion date, internal
creation date
-
UNIX/Linux permissions/file
modes
-
compression/encryption status
-
classification as NTFS
alternate data stream
-
classification as HFS[+]
resource fork
-
classification as reparse
point
-
classification as found in
volume shadow copy
-
classification as file slack
-
classification as file excerpt
-
classification as video still
-
classification as manually
attached
-
classification as virtual
object
-
classification as e-mail
message
-
classification as e-mail
attachment
-
classification as misc.
Outlook data
-
advanced attributes such as
"has attachment", "unread e-mail", "has object ID“
-
sender and recipients for
extracted or processed e-mail
-
skin color percentage and
number of pixels (for pictures)
-
true file type
-
file name/file type mismatch
status
-
owner ID
-
hash value
-
hash category
-
case ID
-
evidence object ID
-
volume snapshot ID
Erweiterte Metadaten werden verstanden von
-
WinHex 16.3 und neuer, mit Specialist-Lizenz oder
höher
-
X-Ways Forensics 16.3 und neuer
-
X-Ways Investigator 16.3 und neuer
-
X-Ways Investigator CTR 16.3
und neuer
|
|
|
|