Description


This script allows the examiner to identify the ancestors of items listed in a given result-set.

This makes it possible, for example, to identify the e-mail that has a compound-file attachment containing files of interest. This will allow the e-mail to be bookmarked and/or extracted.

The script works by scanning the current case and determining the relationships between primary devices (typically evidence files) and the mounted volumes they contain.

This information is stored in a SQLite database, which is then used to construct a tree showing the path to each target item starting with the source-entry on the primary device.

The tree will be presented to the examiner so that he/she can choose the ancestors that should be added to the result-set that will be created by the script.

It should be noted that email certain attachments, e.g., those in PST/OST files, will be contained in a folder of the same name when viewed in the tree presented to the examiner, which represents the entry view rather than the artifact view.

The path of each source-file on the primary device will be shown in the description column.

In many cases, the examiner will want to use this script to identify the PST/OST emails containing notable attachments.

To try and make this process as easy as possible, the script provides an option to select the grandparent of each leaf-node.

This will work provided there is a simple child-parent relationship between each notable attachment and the containing email when viewed in the Artifacts tab. It will not work if the notable attachment is contained in a mounted compound file attached to the email.

The examiner should be aware that the script may take some time to finish particularly if there are many items to process; also if there a large number of mounted volumes in the case.

This script was developed for use in EnCase training. For more details, please click the following link:

Releases

Release
Size
Date
Item Ancestor Resolution 2.0.0
  |  
Aug 1, 2024
More info Less info
Product compatibility
Release notes

Tested with:
EnCase Forensic 8.11.00.74

Languages
English

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-2-1-6322 | Wed Feb 5 16:30:41 PST 2025