Jump to content

jmacedo

Members
  • Posts

    26
  • Joined

  • Last visited

Posts posted by jmacedo

  1. Hello, everyone,

    Just rising up this question, I'm looking to audit what keywords and expressions the reviewers has used or are freely using (terms not included in the previously created and authorized wordlist).

    I could not find it on the case log folder/files or even looking at other direction suggested by section 31 from the Intella 2.2.1 version.

    Did I miss any point looking at this? Is it even possible?

     

    Thank you!

  2. Amazing! I'm thankful for sharing your knowledge.

    In my forensics procedure, normally I execute the acquisition with FTK Imager or a live Linux distribution (to generate a E01 file - one E01 file acquisition per custodian). All E01 files from a specific case are processed with Intella Pro (desktop client) and reviewed with Intella Connect.

    Again, thanks for share your thoughs and if anybody else could share some other feelings, please, do it.

  3. Hello, everyone,

    Sorry if it is a stupid question but I could not find it.

    I'd like to know when (date and hour) a user tagged a document. Is it possible?

    Through document preview function and looking into "Actions" tab I just see that it was tagged, flagged, previewed, etc, but not when the action was done.

    Not even exporting values to an Excel file I could see it.

     

    Thanks!

  4. I see a lot of messages that are supposed to be part of a thread, but when I apply the "Hide Non-Inclusive" button the result is the same.

    It means, I have 1000 results as result of a search and after apply the mentioned button, it remains as 1000 results. I used the last version of Intella to process the case and I'm sure that I marked the new option related to "E-mail thread".

    Also, I'm sure that in this simulation there are e-mail threads. See my attachment, please!

    Am I doing something wrong?

     

     

     

    post-840-0-79811400-1517928714_thumb.jpg

  5. From what I found I could understand that Intella Connect 2.1 is able to read and show whole content of an e-mail thread in a single preview, instead show only a lot of individual files that is part of this e-mail thread.

    If you activate "Hide non-inclusive" in the search tab, only message that are part of the thread will be shown to you.

    Am I right?

    I'm unable to test it right now because I have a client fully using my license.

     

    Thank you, guys!

  6. Hello, everyone,

    Here again with a question:

    My client got 8968 documents through an specific search string. The next step is seperate it in batches with 1000 documents.

    If I keep "Keep items from same family together" assigned, it just created a single batch with 8968 documents. If I unassign this option, I'm able to create a lot of batches with 1000 documents.

    The question is: What is considered family in this case? Type of document (doc, word, pdf), keyword, same search string... Any other thing?

     

    Thank you!

  7. Guys, I'd like an opinion.

    I'm not sure how many of you works with Cellebrite for data extraction.

    Normally, after an extraction, I just generate a XML report through the specific Cellebrite tool (UFED Physical Analyzer) and this XML report is indexed through Intella PRO to allow revision through Connect.

    Do you use or do you see any best way to index a Cellebrite extraction in Intella?

     

    Thank you and regards!

  8. That's right, Jon.

    For a "read-only"I supose that the user should not be allowed to add, delete or modify existing tags, only view.

    Basically I need a user to access a case, review and search for everything that a "common reviewer" did in a case, without the hability to change it.

    A common reviewer is able to create, delete and modify tags.

    I tried several options for this read-only user between what was available through Intella Connect panel, but even with minimum privileges, this user is able to modify and create any tag.

  9. Hello, guys,

    I'd like to create like a read-only user, but doesn't matter what is applied to the new profile, it is still able to add, delete and modify existing tags from documents.

    Is it possible to create this kind of user without permission to add, delete or modify tags on documents?

    I tried to create a user with the following permission: "Can access a case", " Main UI: can use Dashboard", "Main UI: can use Review", "Main UI: can use Search".

     

    Thank you and regards!

  10. Hello everyone,

    My doubt: Is there any other menu inside Intella, where you can check a more accurate evidence size.

    I just perceived that the evidence size presented in the case, after available to reviewers, is equal the sum of all E01 image that I acquired from devices, for example:

    Case 01 = E01 image of notebook (380 GB) + E01 image of server (220 GB) = 600GB as evidence size

     

    Or maybe, the question can be: How do you precify it to your final customer? Normally, it is per GB that is processed, but it makes no sense to charge a customer by 600GB, following my example. It will became something highly expensive, depending on the value charged per GB.

     

    Thank you and regards!

     

×
×
  • Create New...