Jump to content


  • Posts

  • Joined

  • Last visited

  • Days Won


PF1 last won the day on November 6 2014

PF1 had the most liked content!

Profile Information

  • Gender
    Not Telling

Recent Profile Visitors

675 profile views

PF1's Achievements


Newbie (1/14)

  • First Post Rare
  • Collaborator Rare
  • Week One Done Rare
  • One Month Later Rare
  • One Year In Rare

Recent Badges



  1. Amazing Jon, thanks for the heads up on the upcoming adjustment to proximity searches. Many of us have been waiting a long time for this!
  2. Thanks Adam, as always. I should probably grab an ATI card like you suggest. I thought there might be some magic bullet setting in Nvidia or Java that I had forgotten about setting on the old machine.
  3. I just assembled a new workstation and am having trouble with the Intella interface having some nasty display issues. The new machine has an Nvidia GT1050ti video card and is using the 419.67 driver (I know it's not the newest driver, see below). My other machine I run Intella on (older machine) has an Nvidia GTX750Ti with driver version 364.72. Every attempt to update the older machine to newer drivers resulted in Intella issues, so I kept the old drivers in place. On the new machine, whenever I mouse-over any interactive area of the interface, I get second and third and fourth, etc. instances of my Intella screen. My problem is that there is no "older driver" for the new video card, so I tried both the newest and the oldest (currently using) and have the same issues, as seen in the below screen capture of an export dialogue. I replicated the video driver options as best I could between the two machines, but I am still having the same issues. The old machine is W7Pro and the new one is W10Pro. Any suggestions for how to handle? It pretty much makes Intella unusable on this machine.
  4. Wow, I had NO idea the keyword list search adhered to the check boxes under the individual keyword search box. That makes things much easier, thanks!
  5. What about excluding path hits when using a keyword list (no checkboxes for search options)? I seem to recall there being a way to prepend each keyterm in the list with something like 'notpath', but I cannot find where I think I recall that from.
  6. That would be more than acceptable to me, and i understand the overhead. Perhaps it makes sense to use a single size delineation for the size column (i.e. all KB, all MB or all bytes).
  7. That's the thing, I DO need to use this many times per day when working a case in Intella. Many other forensic tools allows for this (EnCase, X-Ways, etc.) and it's a really useful feature. Otherwise, I end up having to export listings five or six times (or more) just to find out what the total resulting size of a keyword search results will be based on variances in the search term list and how the results are assembled. Since Intella is already computing the individual sizes of items in the "size" column, I guess it didn't seem like it would be all that difficult to integrate a feature that would 'sum' the size of the highlighted results.
  8. This request has been made a few times before, but I am not sure if it will ever make it into a version. I would like to be able to highlight multiple items in the table pane and have Intella tell me the total size of the items highlighted.
  9. Currently, when I run a keyword search that contains more than one keyword, I need to open each resulting item in the preview to see (at the bottom of the preview) which keywords have hits in that item. It would be great if a column could be added to the table view that contained any/all keywords resulting from a search. The data should be available, as the preview of each result shows the hit terms.
  10. I recently ran a keyword search across various email PSTs and was viewing the hits. Some hits were email bodies and other hits were in attachments only. I highlighted the entire list of hit results and right-clicked and selected show parent (direct, not top level). I then tagged all these items with the thought that any attachment would now have its parent email tagged. I exported the tagged items as native, but there were a number of instances of where the parent email of the keyword-hit-attachment did not appear in the export. In order to test this, I found one such email/attachment. The attachment had a keyword hit but the parent email was no included in the export. I previewed the attachment and from the preview window (left side) selected "show parent" and sure enough, the parent email appeared. I noted the parent email's Item ID and closed the previews. I then selected the attachment and about 50 others as a group in the listing and right clicked -> "show parent" and the parent item ID was not in the resulting list. Obviously, this caused a lot of concern as I am now unsure if all parent item emails are being selected when I highlight a group of keyword hit items and right click -> "show parents." Does anyone have any thoughts on why this occurred? My goal was to export the lowest level email item possible (including any of it's attachments) for any item (be it an email or an attachment) with a keyword.
  11. I guess in the future I could select each of the individual MBOXs from the IMAP collection except the ALL MAIL MBOX, index the collection, and then add the ALL MAIL MBOX in as a second step. Anything that was a duplicate in ALL MAIL would be duped out. As a workaround, I showed the "duplicates" column in the listing pane, sorted based on location and tagged for export any item in the ALL MAIL location that did not show a duplicate, but did not tag any item that did show a duplicate. All other relevant items from other Gmail 'folders' were tagged and all tagged items were exported.
  12. I am wondering if there is a way to control the order of analysis for deduplication. I frequently collect GMail IMAP accounts and find that the ALL MAIL folder generally holds a duplicate of messages located in other GMail folders (well, Gmail tags, really). But, it is entirely possible that a user could place a message into the ALL MAIL folder on his own and it would be the only instance. What I am wondering is if there is a way to have Intella review for duplicates whereby the All MAIL folder (or any folder) is assigned the lowest priority? Given an email that is present in ALL MAIL and also STARRED, I want the ALL MAIL version excluded and the STARRED one to remain. However, if a message only exists in ALL MAIL, I want it included in my end result (so I cannot simply exclude the ALL MAIL folder completely).
  13. Chris, great suggestion. Thanks. I forgot that Message-ID is an available column. I wonder, though, since it is already being extracted for display in the column, why it cannot be used as a search field.
  14. I understand this, but in my case this does not work as I also get all OTHER messages in a conversation (since the Message-ID appears in the header of the other emails in the conversation). That's why I am posting this in the "wish list" thread. I am hoping Vound can make the message-ID a uniquely searchable field, like some of the other specific fields that can be searched. Message hash is not necessarily unique, as the tool used to generate it may use different data to compile it (x-ways vs. Intella vs. Relativity, etc.), but the message-ID is unique to the specific email, so it would be useful to be able to search just on the message-ID.
  15. Any updates on this? I am working on a case with ~13,000 search terms, and since Intella seems to not work with a keyword list of over 200 message ID or email Subjects (error= Query is too long), I am having to break the list into 50+ small keyword lists. It would be great if I didn't have to import each one individually.
  • Create New...