lab-12-Email forensics
lab-12-Email forensics
Step 2.
List all e-mails of the suspect. If possible, identify deleted e-mails
• Install email extracting tool: libpff
• Copy .ost file from a DD image
• Extract email via libpff
Install pffexport tool
1
Verify installation
2
Access a message in suspect’s IPM_SUBTREE
ls -l iaman.informant\@nist.gov.ost.export/Root\ -\ Mailbox/IPM_SUBTREE/Inbox/
cat iaman.informant\@nist.gov.ost.export/Root\ -\
Mailbox/IPM_SUBTREE/Inbox/Message00001/OutlookHeaders.txt | grep -Ei "time|suject|
name“
grep -E ‘strings’ Message*
3
YOU MUST SUBMIT A FULL-SCREEN IMAGE FOR FULL CREDIT!
Save the document with the filename "YOUR NAME Lab 12.pdf", replacing "YOUR
NAME" with your real name.
Email the image to the instructor as an attachment to an e-mail message. Send it
to: [email protected] with a subject line of "Lab 12 From YOUR NAME", replacing "YOUR
NAME" with your real name.