Jump to content


  • Content Count

  • Joined

  • Last visited

  • Days Won


AdamS last won the day on March 27

AdamS had the most liked content!

Community Reputation

30 Excellent

About AdamS

  • Rank
    Advanced Member

Profile Information

  • Gender
    Not Telling

Recent Profile Visitors

849 profile views
  1. Alternatively you could produce a report of the messages to CSV, then copy out the relevant message you are interested in.
  2. Sorry Vince the issue didn't occur again so didn't chase it any further
  3. AdamS

    What is W4

    Okay some initial feedback. Firstly, I just want to acknowledge that I know this is a first release Beta so some of my thoughts below are likely already on the map, and some are likely far down that map. But my initial excitement about this software wasn't misplaced. I'm extremely impressed and can't wait to see how this develops. I can already see a place for this tool in my day to day work life. Testing Notes I threw in an image of a PC and an iMac just for giggles, I'm guessing at this early stage the concentration has been on support of Windows OS as much less types of artefacts for the Mac was identified, but I was kind of expecting that for such a new bit of gear. Test Machine Specs Core i7 with 64GB ram running Windows 7 x64 Installation Install went smoothly, however did take around 45 mins. I'm assuming that as a first beta release this is pretty low on the priority list and I would expect that to improve and change as the package develops. Case Setup Case setup extremely simple, just a couple of fields to fill in then point to the disc image to ingest. Processing 120 GB - Started at 1800 hrs 25/10/18 1 min – Identified user accounts and other artefacts started appearing after 1 min processing 48 min total processing time 1TB iMac image - Started at 1900 hrs Again within 1 minute I was seeing data and could triage results 1hr 13m total processing time Notes No video or audio ‘open in external application option’ possibly intentional at this stage. Other viewers seem to work for pic and docs Thoughts and Ruminations USB Logs Would be nice to see some other info here if it's possible to show any file movement or access at the same time as the devices are connected The links view shows the user account that was logged in, would be nice to see this in the events view as well, maybe far right side in the boxes for each item? Event log viewer Would be nice to see more information around the event types, maybe another tab next to the ‘properties’ tab when selecting a log. Filter ability to isolate specific types of event logs, possibly addition of auto filter for event logs that might be of common interest ( shutdown/startup, virus scan, windows update, windows restore, restore point creation) Notable Program Usage Expand notable program usage (likely already high on the list) maybe ability to filter here from a predefined list (check box), possibly the ability to add custom programs based on the .exe name. In my head I'm seeing something similar to what IEF use when determine which app artefacts to go looking for. Deleted file activity Would be great to add tab next to ‘properties’ tab to show more information such as which user was logged in at the time, can currently see in the links view only. User Profiles The ability to filter all events based on a user profile, ie build a full timeline of activity for a single user by session linkage. Geolocation Would be nice to have a map with GEO location items (for offline use) AND direct link from the Geolocation field to google maps for online use. Cosmetic Stuff Collapse/Expand all option in search window for facets Create thumbnail pics for video files Data Support Support for mobile phone artefacts like iPhone backups, also to identify those backups which can’t be parsed due to encryption (possibly out of scope but given Intella support already of UFDR files this would seem to be a natural progression) Can UFDR files be imported yet, on the roadmap? Virus scanner logs showing quarantine events, etc Firewall Logs I also noted the picture review is nice and fast, the thumbnail caching works fantastic. Great for onsite triage of pics for LEO. I will spend some quality time over the coming weeks to really dig into this, but this is my initial thoughts after a few hours of playing.
  4. AdamS

    What is W4

    Just quietly I'm excited. Downloaded and started testing on a 120GB disk image, within 1 minute of processing starting I'm able to start triaging and seeing valuable data. I'll withhold any more comments until the indexing process finishes and I can spend a few hours coming up with some constructive testing, but what I've seen in the last 30 minutes or so has me massively impressed. Edit: sorry just one comment, I love the Events view. A good timeline tool has long been something missing and the way this presents the data is exceptional. I'll be watching closely to see how the reporting side of this tool develops, as traditionally this is where it can get tricky. Porting those timelines out into something useful for clients or third parties to use.
  5. I'll check on that next time I'm at that particular clients as I don't have access at the moment.
  6. Just wanting to revisit a wish I had from 2015 to bring it back to life. The timeline view for intella, currently we can't do anything except export to PNG graphic file. Adding the ability to export to HTML or Excel would be a huge benefit. I'm constantly asked for timeline graphs/presentations from clients and have to resort to looking at other Analytics tools which are not exactly built for simple timelining, although they do an admirable job it seems a pity to waste the perfect timeline already showing in Intella.
  7. Yes sorry, that's the option, and I should have clarified this is being seen on Intella Reviewer only.
  8. I'm seeing some unusual behaviour and wanted to check if anyone else has seen this. When previewing an email we go to "print report" option, we then have two "yes/no" questions to answer (Include Attachments AND print preview view) which we select yes on both. When the print preview appears the second page of text containing the bulk of the email body is blank. This only occurs when selecting the "print preview view" option, if we select no for that option then the print window renders the 'content' view and there are no issues. My first thought was that this was an HTML rendering issue as the computer in question had IE as the only browser, so I installed Chrome, made sure that was the default browser and the issue appeard to go away. However it has no reared it's head again and the second page is always blank.
  9. Hi John, I'm sure there is a way to acheive what you want using various AND / OR functions and the inlcude/exclude options, however I've found that building complex searches with simple steps gives a good result and some comfort that you are getting the results you wanted. To accomplish this I would use the following method: In the Facet Search windows select Type then in the window below select Communication-->Email and click search Click on the big ball to select emails then go to the keyword search window (top left), click Options then put tick in the boxes From and Sender Click on Search again to close this little window and type the email address in the Keyword search window then click search You should now have 3 balls in the Results window, click on the middle intersecting ball which should be all the emails sent From the email address In the Details window select all these itmes and tag them all "Emails AND From Address" or something that makes sense to you Clear everything Repeat step 1 and 2 only this time at step 2 tick the boxes for To, Cc and Bcc You should have 3 balls again, select the intersecting ball and tag those results "Emails AND To Address" or similar You now have 2 working tags with all your emails TO and FROM the relevant email address. To isolate those with attachments simply bring the tag up by highlighting the tag and clicking search. Ensure the "has attachments" box is ticked in the Column selector (small box with green tick directly under the word timeline, middle right side of screen). You can then sort the emails based on that filter and highlight the ones with attachments and tag those accordingly. It seems like a lot of steps, but trust me the more you use the software the quicker things move, that process would generally only take a minute or so.
  10. Hi Jon, just thought I'd check in on this question to see if there is any update.
  11. Thanks John, I'll delve into that and see how we go
  12. Intella has pretty strong inbuilt support for detecting and identifying different languages, however I'm in a position where I have a large number of Japanese documents/emails etc and wondering what my options are here. Does anyone have any experience with translating documents of this nature in such a way that I can still make use of Intella for review?
  13. Jon is this specific to Intella TEAM when importing the work product from viewer licenses? I know there has been talk in the past (and it was hinted that it was not far away) of full case merging rather than just importing the work product from Viewers. By that I mean two completely independant cases with different custodians etc..
  14. Hi John, I can't see an email thread tab in the preview window, there is however the email thread listing under the facet search window. It could be that I'm misunderstanding how the "hide non-inclusive" function is meant to operate, I just took it literally. Even when I go to the "email thread" facet option and pick one of those items with multiple emails listed in the thread, selecting or unselecting the "hide non-inclusive" option has no effect. Edit: There may be something deeper going on with this data set as I looked in the "non-inclusive" field for the Details window and no emails are showing under this field, so that makes perfect sense that the hide non inclusive would have no effect. I will re-run the email threading process and tick discard previous threading data to see if perhaps something went awry with the original threading process.
  • Create New...