Description


This EnScript will search for, and bookmark, ZIP-file index-entries. It was designed for the recovery of data from deleted ZIP files (including MS Word *.DOCX files) that can't otherwise be recovered, either because they're partially overwritten or fragmented.

Each file in a ZIP file has a 'central' and 'local' ZIP-index-entry. Amongst the data contained in each entry is the file's relative path and file-name, last-modified date, compressed size, uncompressed size and CRC-32 value. The central index-entry for a file also has a comment field. The CRC-32 and file-length index-values for internal ZIP folders are always set to zero.

The user has the option of extracting the results into a tab-delimited file, which can be opened using Microsoft Excel, or if there are a large number of entries, imported into Microsoft Access.

In addition to extracting the index details, the user can also opt to extract the data comprising each local-index and the compressed stream that follows.

The extracted data will be written in the form of a pseudo ZIP file that the script can attempt to repair and decompress if so requested.

The name of each pseudo file will be in the following format -
  • <Extraction Index>_<Evidence Name>_Raw_<Entry Name>_<Offset>_<Length>.zip
Each ZIP file that has been repaired will be named as follows -
  • <Extraction Index>_<Evidence Name>_Repaired_<Entry Name>_<Offset>_<Length>.zip
If a repaired ZIP file can be decompressed, the resultant file will be named as follows -
  • <Extraction Index>_<Evidence Name>_Decompressed_<Entry Name>_<Offset>_<Length>.<filename>
Should the repair of a given file fail, it may still be possible to repair it using an application such as WinRAR. This particular application can repair multiple archives at the same time.

Corrupt ZIP archives can also be repaired by EnCase. To facilitate this, the output of the script can be written into a logical evidence file (LEF).

The script has an in-built filtering capability, which allows the examiner to process only those index-entries that match the filter-criteria specified by the examiner.

These criteria can specify the relative-path/name, last-modified date, decompressed size and CRC-32 value. Note that the filter-dialog presents the CRC-32 value as a string rather than an integer value. This avoids the examiner having to enter it either as a decimal value or a hex value preceded by '0x'.

All settings (including the filter criteria) are remembered for later use.

This script was developed for use in EnCase training. For more details, please click the following link:

Releases

Release
Size
Date
ZIP Index Entry Finder 7.1.0
  |  
Aug 1, 2024
More info Less info
Product compatibility
Release notes

Tested with:
EnCase Forensic 21.01.00.68

Languages
English

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-2-1-6322 | Wed Feb 5 16:30:41 PST 2025