设为首页 收藏本站
查看: 970|回复: 0

[经验分享] Searching for Outlook Compressible Encryption (PST Data) in the Unallocated Clu

[复制链接]

尚未签到

发表于 2015-9-14 08:44:25 | 显示全部楼层 |阅读模式
Creating Search Terms with Outlook Compressible Encryption (OCE) Code Page
Viewing Search Hits with (OCE) Code Page

Bookmarking (OCE) Search Hits with (OCE) Code Page


Return to Main Forensics Help Page

When PST data rolls off the PST file and becomes located in unallocated clusters, various methods can be used to recover it, some successfully and some not.  Usually these are shotgun approaches that fail.  If you use a precise "rifle shot" approach, you can recover email data with good success.  In essence the above three steps are the three key elements in getting the job done.  If any images below are too small right click on the image and save the picture to your system to view in whatever size format that works for you.

What makes all this possible is the judicious use of EnCase's Outlook Compressible Compression Code Page.  With it, you can fashion a precise search for PST data.

The first step is to create a keyword and to create it using the Outlook compressible encryption code page.  The below two diagrams show the creation of the keyword and code page.  Turn on Unicode as it will then find both Unicode and non-Unicode occurrences and turn off the Active Code page to limit your search hits to the OCE code page.

DSC0000.jpg

DSC0001.jpg


Once you have created your keyword with the OCE code page, select the unallocated clusters for your search.  You could search other places as well, but for now, let's stick with UC for demonstration purposes.


DSC0002.jpg

Click on the search button to setup your search criteria, as shown below:


DSC0003.jpg


Run your search and then visit the search hits view to see what you found.  When you look at the search hits that are found in OCE (PST data), they appear as gibberish when viewing through any of the establishing text styles as shown below.

DSC0004.jpg

To view them, you need to create and apply an OCE text style.  Go the the text styles view, right click and choose new.  Set it up as shown below:

DSC0005.jpg

DSC0006.jpg

Make sure you visit the code page tab and turn off the Unicode, choose "other", and choose #48 "Outlook Compressible Encryption".  Once you have created the code page, click ok and then select that newly created code page.  When you do, the data will be viewed through this code page and the gibberish will snap into clear text as shown below.

DSC0007.jpg

Select any text you wish to bookmark, right click and choose to bookmark the data as seen below.

DSC0008.jpg

Once you are in the bookmark dialogue box, the OCE code page that you just created is now available as a view type.  Select that view type and your bookmarked data will have the OCE code page applied and you have now successfully search for, located, and bookmarked OCE (PST data) in the unallocated clusters.  It's all made possible via the OCE code page.


DSC0009.jpg



运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.iyunv.com/thread-113257-1-1.html 上篇帖子: 当Outlook无法自动检索邮件服务器设置时…… 下篇帖子: Microsfot Firewall Client引起Outlook Express无法收发邮件的问题
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表