Jump to content


  • Content Count

  • Joined

  • Last visited

Community Reputation

0 Neutral

About llanowar

  • Rank
    Advanced Member

Profile Information

  • Gender
  • Location

Recent Profile Visitors

1,235 profile views
  1. I have successfully added a few sources to an Intella Pro case (E01s and folders). I am attempting to add one last E01 image and am receiving the following message in the "Select Folders" window: "Unable to retrieve folders." Note: I loaded this problematic image in another tool (XWays Forensics) and am able to see the partitions and folders tree. I tried re-imaging just the primary partition in the E01 using XWays and adding to a new Intella test case: same issue "Unable to retrieve folders." Any ideas on what may be causing this / how to fix? Thanks group.
  2. I am poking around W4 1.0.3 for the first time - using the NIST CFReDS "Data Leakage Case" data set. I am really liking what I am seeing so far. One irregularity I just ran into: In the "USB Devices" Search section, the "Items" view correctly lists the connection timestamps (even after applying an EDT timezone offset in the "Sources" tab). The irregularity occurs when switching over to the "Events" view. The connection timestamps are all off by exactly 1 hr (likely a Standard/Daylight Savings issue). In the "Events" view, the right-side "Properties" preview section lists the timestam
  3. I have processed a Cellebrite UFDR file (phone) with Intella v2.2.1. The manual makes it clear that instant message items will be bundled into "conversation items" if able, on a day-by-day basis (page 62). My question is: Is it possible to tag only one of the bundled message items listed in the bundled conversation? Tagging seems to only apply to the entire bundled conversation "SMS/MMS Conversation" file. One idea - perhaps I must redact all of the other/unwanted bundled text? Thanks
  4. Thanks for the reply. When I have the next opportunity, I will check the item's Raw Data tab.
  5. Dear community, I sent off a Cellebrite phone collection to be reviewed (along with the UFED Reader application). The reviewers tagged a bunch of items using Cellebrite Reader and then saved the results in a .pas (session) file. They now want me to create a load file of their tagged items. My thoughts: perhaps they can just email me their .pas session file containing their Cellebrite tags, I can load it up in Cellebrite (along with the original phone data), generate an XML report (which will hopefully contain their tagged items identified), use that XML report folder as a source in I
  6. I did resolve my issue above (sort of). I exported as a load file (including PDF versions in the images export section). The contents of the PDFs folder is what I was wanting. I just deleted the rest of the load file pieces. I will experiment with the PDF export options some more to see how I can achieve what I wanted with just a PDF export (rather than load file).
  7. I am using Intella Pro 2.2. I am attempting to export as PDF a few email messages with attachments. I selected the "Number pages" checkbox, but my resulting PDF files (3x, one per email) do not contain a page number. Each of the 3x exported PDF files' names increment correctly, based upon the number of pages within each. EX: 0001.pdf, 0006.pdf, and 0010.pdf. - But within each PDF, each page is not numbered. Is there perhaps an option I need to select on the "PDF rendering options" export page? or perhaps on the "Headers and footers" export page? Thank you.
  8. Thanks for the reply. I am using default settings for Intella 2.2. The Wizard window1 settings are just pointing to the .DAT and .OPT files. The Wizard window2 settings are default and I double checked them with the specification in this matter: Condensed spec I received: 1. fields delimited with ANSI 20 2. String values within fields should be enclosed with ANSI 254 3. First line should contain metadata headers then one line per document 4. each row must contain the same number of fields as the header row 5. Each return or new line delimited by ANSI 174
  9. Hi group. I am attempting to import a load file source (Concordance). After step 1: pointing to the .DAT and .OPT files, and hitting step 2 (Configure Delimiters) I see at the bottom, "Error while validating load file: Input length = 1. I am not very savvy with load files and this may be beyond my capabilities to resolve - but I thought I would at least see if this particular error message may have an easy fix. I clicked "Detect encoding" and receive: "Could not detect encoding". The "Load file preview" tab is blank. The "Image preview" tab shows a page name, a image path beginning w
  10. Hi group. I am performing my fist exports of tagged data with Intella and am wondering if you have any pointers/suggestions for a good naming/numbering scheme. The protocol does not specify any specifics for naming/bates stamp conventions. - just that each tiff/page needs a unique number with no gaps. One party wants a load file (with TIFFs), another party wants just PDF renderings of everything (they don't use a review platform). I suppose I could perform the export as a load file "type" (export screen 1). On the "Load file options" screen I can check both the "Include image fi
  11. Amazing! Thanks - I'll give it a whirl later today. As always, thanks for the assistance.
  12. Hi group. I am using Intella Pro 2.2. I have been asked to produce some tagged files in load file format. The protocol states a field should be included, "CONFIDENTIAL", "Y or N will be noted in this field. This field defines whether or not a document has ben designated as "Confidential."" I have researched the load file creation screens and do not see how to include this field. On the "Load file options" screen, I checked "Exclude content" with the confidential tag applied and the Placeholder text "CONFIDENTIAL." On the "Load file field chooser" screen I see no way to
  13. I have a question about creating a load file. One of the load file metadata fields I was instructed to incorporate is (per the ESI protocol doc): ATTACH_RANGE Description: Beginning and Ending Attachment numbers for parent and children. The number should be BEG_NO of the parent and END_NO for the last Child. Looking at page 190/191 of Intella manual, this seems they want RECORD_ID_GROUP_BEGIN and then RECORD_ID_GROUP_END. If so, then how would I associate two Intella types to one new custom field "ATTACH_RANGE"? Thanks.
  14. I searched for an OCR candidate procedure and ran across this older conversation (as well as the "Sample checklist for users" post). I still am wondering ... Using Intella, how best to identify the files I should OCR? Perhaps, use the Images "Type" facet and preview all of them? Preview all of the "Empty Documents" in the "Features" facet? Are the above 2 steps alone satisfactory? Any guidance on a procedure(s) to locate files needing OCR would be very welcome
  • Create New...