
arjohn
Administrators-
Content Count
22 -
Joined
-
Last visited
Community Reputation
1,000 ExcellentAbout arjohn

-
Rank
Staff
Profile Information
-
Gender
Not Telling
-
Cellebrite XML Report source with Cellebrite tags
arjohn replied to llanowar's topic in Intella 10, 100, 250, Pro and TEAM
Hi llanowar, Can you check if the tags are shown in the item's Raw Data tab? Also, would it be possible to send us a (redacted) sample of the XML file for investigation? Feel free to open a support ticket if this is possible. -
Hi Adam, You could have a look at the new command line options that are offered by Intella 2.2. Using a script you should be able to use, for example, Google Cloud's AI service to translate such documents and import them back into Intella. See also chapter 27 of the user manual. We'd be interested in hearing your experiences with this option.
-
Examining Outlook and S/MIME Encrypted E-mail
arjohn replied to Hagrid's topic in Intella 10, 100, 250, Pro and TEAM
Decryption of S/MIME has been added to Intella many years ago, so I don't expect any issue with this. -
Maybe it helps to have a look at the Email Thread tab in the item previewer and see if any of the emails are shown as non-inclusive.
-
Hi Ken, Including the URL in a CSV export is currently not possible. We will try to make this possible in one of the next releases.
-
Visited URL's review
arjohn replied to Questa Integrity's topic in Intella 10, 100, 250, Pro and TEAM
This is currently not possible, but we can see why this would be a good idea. I have added feature request for this to our roadmap. -
The second options sounds the most logical one, but it really depends on what you're after. Assume you have two emails that have the same attachment and a search that matches this attachment. Deduplicating the set first will remove one of the matching attachments and the export will only contain one of the e-mails. Doing it the other way around will get both e-mails in the export.
- 3 replies
-
- deuplication
- de-duping
-
(and 2 more)
Tagged with:
-
Hi Adam, The answer to your question very much depends on how heavily the machine is used. If you're hosting one or two cases to just a few reviewers then the single CPU will likely be more than enough. On the other hand, if you're sharing many cases to many reviewers then having more cores helps. Just keep in mind that the installed RAM can quickly become a bottle neck when scaling up to more shared cases.
-
AOL Personal Filing Cabinet Files
arjohn replied to fuzed's topic in Intella 10, 100, 250, Pro and TEAM
Hi fuzed, Emailchemy can read various AOL file formats and convert these to EML files, which can then be processed by Intella: http://www.weirdkid.com/products/emailchemy/ -
Insight Tab in new version 1.9.1
arjohn replied to JNevins's topic in Intella 10, 100, 250, Pro and TEAM
Hi, Thanks for your feedback and good to hear that you love the new functionality. USB mass storage dates: we have deliberately excluded these dates for now as they are notoriously inaccurate form time to time. For example, some dates for devices are updated when other devices are plugged in. As such, it takes quite a bit forensic knowledge to interpret these dates correctly. We do intend to include these dates in a later release, when we can present these in a way that doesn't put investigators on the wrong track. Browser activity: can you let us know where these URLs, cookies and -
arjohn started following Intella 10, 100, 250, Pro and TEAM
-
Hi, We're regularly testing with Russian texts, so I don't foresee any difficulty here.
-
Hi, Maybe the Windows Task Scheduler can be of use to you? If you run Connect as a service, you could add a task to shut it down after office hours and start it again the next day.
-
Hi SamW, The histogram indeed shows the results for all items in the case. We are planning to add both filtering and export options, but we can't predict when this will be available yet. With respect to deduplication: note that even duplicate items can have different dates associated with them. Dates that are extracted from/associated with the item content will be equal, but dates that are external to the item content (like file system dates or dates stored in a PST file) can be different. As such, item deduplication in this histogram will be problematic. The only option that I can thi