Forensic Image Handling

The eCapture installation includes a File Mounting Service (FMS) to support forensic file image handling in Enterprise. When a forensic disk image is encountered inside a discovered data set, the image is automatically mounted to allow for discovery and data extraction. Forensic image files may also be mounted and discovered directly from the eCapture Controller automatically.

Two third-party applications may be used for mounting forensic image types: Mount Image Pro and OSFMount. The FMS uses Mount Image Pro by default. Only one third-party application may be used at a time.

Mount Image Pro

Mount Image Pro supports the following forensic file image types:

Forensic Category

 

Description

 

Extension

 

Detection Method

 

Access Data

Access Data

.AD1

Bytes

Apple

Apple Disk Image

.DMG

Bytes

Encase

Encase File

.E01

Bytes

Encase

Encase File

.EX01

Extension

Encase

Encase Logical File

.L01

Bytes

Encase

Encase Logical File

.LX01

Extension

Encase

SMART

.S01

Bytes

Forensic File Format

Advanced Forensic File

.AFF

Bytes

Raw CD Image

ISO Optical Image

.ISO

Bytes

Raw CD Image

Nero Burning ROM

.NRG

Extension

SafeBack

System Deployment Image

.SDI

Extension

OSFMount

OSFMount supports the following forensic file image types:

Forensic Category

Description

Extension

Detection Method

Encase

SMART

.S01

Bytes

Forensic File Format

Advanced Forensic File

.AFF

Bytes

To use OSFMount instead of Mount Image Pro, it is necessary to manually update a property table in SQL.

Note: Now the system is using OSFMount. To switch back to Mount Image Pro, PropertyValue must be changed from 2 back to 1.

 

To discover the additional forensic image file types .S01 or .AFF, it is necessary to update the property table and run the following SQL query:

update enterprise.ApplicationEnvironmentProperty

set PropertyValue = 2

where ApplicationEnvironmentPropertyNameId = 4

 

Related Topics

Introduction to eCapture