Item Ancestor Resolution
This script allows the examiner to identify the ancestors of items listed in a given result-set.
This makes it possible, for example, to identify the e-mail that has a compound-file attachment containing files of interest. This will allow the e-mail to be bookmarked and/or extracted.
The script works by scanning the current case and determining the relationships between primary devices (typically evidence files) and the mounted volumes they contain.
This information is stored in a SQLite database, which is then used to construct a tree showing the path to each target item starting with the source-entry on the primary device.
The tree will be presented to the examiner so that he/she can choose the ancestors that should be added to the result-set that will be created by the script.
The path of each source-file on the primary device will be shown in the description column.
The examiner should be aware that the script may take some time to finish particularly if there are many items to process; also if there a large number of mounted volumes in the case.
YOU MAY ALSO LIKE