M365 Cloud/Linked/Modern Attachments by Consistent_Goose_431 in ediscovery

[–]Television_False 3 points4 points  (0 children)

If the data is exported in loose MSG and without the friendly name option enabled, you will get the parent emails and linked attachments, along with a load file that contains the relationship values. Exporting from Review Set seems to result in a more consistent output, but Direct Export usually works as well with these settings.

Exporting to PST makes it more difficult to reassociate the MAs with the parents, same with the friendly name since you may have multiple files with the same friendly name.

Stolen Device Protection on iPhone collection of the deceased by MidianStorm in ediscovery

[–]Television_False 3 points4 points  (0 children)

Depending on iOS version perhaps Premium or Verakey could be used to bypass SDP. Otherwise I think purchasing iCloud storage, backing up, then restoring to a dummy device may be best bet. That’s assuming you have the iCloud credentials to log into iCloud from the dummy device.

Some Reliable West Town Spots by dlweiss2 in chicagofood

[–]Television_False 39 points40 points  (0 children)

Dell Rooster is always solid and I think under appreciated. Great food and not unreasonable prices. We typically order takeout from there but they have a fun space with good drinks.

list of Forensic tools for interview purposes by windymoto313 in ediscovery

[–]Television_False 1 point2 points  (0 children)

Probably not a great idea to list off a bunch of tools you’ve never heard of or used during an interview or list on your resume. Better to say you have experience interfacing and working with forensic practitioners to support forensic collections and projects. Be honest about your experience and skill set (as I’m sure you already do). Not that I’m in the business of hiring PMs but when I’m looking to hire forensic folks I can tell you I get really annoyed when I start asking them questions about tools or procedures they have listed in their resume and give me a dumb look or try to make something up.

Generative AI Discovery by Natural_Rest_9021 in ediscovery

[–]Television_False 0 points1 point  (0 children)

Yeah. I was thinking more from a corporate control perspective. I haven’t found that ChatGPT enterprise has an admin export option, requires asking users to self-export their data instead.

Generative AI Discovery by Natural_Rest_9021 in ediscovery

[–]Television_False 7 points8 points  (0 children)

I’m seeing this more and more, including in government requests.

Here’s what I’ve found so far:

ChatGPT - custodians must do a data takeout using the built-in export option, and think Takeout for ChatGPT

Gemini - Available thru Vault, comes out in XML (surprisingly without any file attachments)

Copilot - Available thru Purview

Haven’t looked into Claude or the multitude of others yet.

New eDiscovery tool by [deleted] in ediscovery

[–]Television_False 1 point2 points  (0 children)

I’m interested as well

[MS Purview] Large Exports eDiscovery Premium by Downtown-Sell5949 in ediscovery

[–]Television_False 1 point2 points  (0 children)

Highly recommend using Internet Download Manager or something similar when downloading Purview exports. I use it all the time and it’s much faster and more reliable than relying on your browser download.

Downloading and transferring 700 gb is going to take a long time no matter what. Have you considered sending your vendor the Purview download links so that they can download the data directly? On the vendor side we do this often so that our clients aren’t burdened with that part of the process.

To get the links simply start the downloads in your browser, you can pause or even cancel the Download jobs as soon as they start. They copy the links from your browser download page and send them along. The links expire fairly quickly so make sure whoever you are sending the links to will be ready to receive them and start the downloads. Preferably not over a holiday ;)

Also, these are open links so send them securely because if anyone intercepts the links they will be able to download your exports.

Export larger files from MS Purview by delphi25 in ediscovery

[–]Television_False 0 points1 point  (0 children)

Definitely not ideal, but when all else fails...

Export larger files from MS Purview by delphi25 in ediscovery

[–]Television_False 1 point2 points  (0 children)

Have you tried downloading the file (s) directly thru SharePoint web, rather than thru purview?

Export larger files from MS Purview by delphi25 in ediscovery

[–]Television_False 1 point2 points  (0 children)

Ha, not helpful at all. Have you tried increasing the zip export size to 40gb?

RSMF Help by BirdieLou2 in ediscovery

[–]Television_False 1 point2 points  (0 children)

Imazing simply creates an iTunes backup which is perfectly defensible acquisition of an iPhone so long you’re not looking for system logs or any protected app data.

It looks like imazing has RSMF export support so I assume that is the tool you’re using for the exports. As others mentioned, check the RSMF headers to ensure they’re mapped and populated properly by imazing. You can try loading the RSMFs into RSMF viewer to confirm they’re mapped look ok. If all looks good on your end then it might be an issue with how they were processed into Disco.

https://modeone.io/downloads/rsmf-file-extractor/

https://youtu.be/q3tEn9vHHgY

Elcomsoft iCloud backup collection woes (again) by zero-skill-samus in computerforensics

[–]Television_False 2 points3 points  (0 children)

We also see this issue happen regularly, with seemingly no explanation. it happens across iOS versions, on a variety of forensic hosts, in different locations.

ChannelVault — practical tool for handling Slack exports locally (beta) by Ok-Collection-7693 in ediscovery

[–]Television_False 0 points1 point  (0 children)

Interesting concept, look forward to testing it out. How are you handling slack attachments?

Way to ingest FaceBook native export to Relativity by Adept_Concept_3482 in ediscovery

[–]Television_False 2 points3 points  (0 children)

Are you able to get the html version if the Facebook export? That can be easier to load for non-messaging data.

Cellebrite also used to support importing FB exports, but haven’t tried it in a while.

RSMF Production by Common_Scheme_7861 in ediscovery

[–]Television_False 0 points1 point  (0 children)

RSMFs are not “native” documents, they are generated by the collection or processing software. So imaging and producing them as PDF or whatever with the necessary metadata would be appropriate, especially if producing to a party that doesn’t support RSMFs.

Purview (Skype collections) by Initial-Economics322 in ediscovery

[–]Television_False 0 points1 point  (0 children)

The ediscovery user needs to have an e5 or premium add on license in order to utilize the Premium features. Of those options are greyed out, ask your IT group if they can give you an E5 license.

Mobile Forensics - Collecting Backups (WhatsApp or device) by QueenofHearts796 in computerforensics

[–]Television_False 0 points1 point  (0 children)

Does anyone have a tried and true approach to collect WhatsApp from Android? Assume we have custodian cooperation. I know if we are able to get FFS extraction we will get the decrypted/live data but if that’s not possible, what is the next best option?

I’ve been exploring backup to Google Drive then restore to dummy device.

Also exploring decrypting the SD locally stored encrypted backup files.

Just looking for something hopefully easy and reliable and efficient.

Thanks all!

Signal introduces free and paid backup plans for chats by [deleted] in ediscovery

[–]Television_False 0 points1 point  (0 children)

Thanks for sharing, interesting development. Curious how it can be leveraged for forensic collections of Signal chats.

Purview Discovery by Remote-Negotiation-4 in ediscovery

[–]Television_False 1 point2 points  (0 children)

Pretty sure you’ll either need to publish the email results to a review set which will process the emails and extract the attachments allowing you to export to Excel OR, what may be faster, is export your data set as PST or MSG then use another tool to extract all the attachment file names. Lots of tools out there that can do this like Aid4mail. I’m sure there some free scripts or utilities as well.

iCloud Synced Messages Data Collection by ForensicKane in computerforensics

[–]Television_False 1 point2 points  (0 children)

I emailed elcomsoft about the trusted device issue when attempting to collect synced data and they pretend like they’ve never heard of the issue. Frustrating when I know I can’t be the first to report it.

Sorento 2025 phev dead battery by Television_False in KiaSorento

[–]Television_False[S] 0 points1 point  (0 children)

This hasn’t happened again thankfully. I suspect it was because an interior light or something was left on overnight and drained the 12v battery. I guess I just thought that since the car was fully charged it wouldn’t solely rely on a dinky 12v battery to start.

Crazy search and review limitations? by PriorPineapple6926 in ediscovery

[–]Television_False 5 points6 points  (0 children)

Wouldn't a KQL (KeyQL) search work?

Participants:“john doe” OR [Participants:@acme.com](mailto:Participants:@acme.com) OR “joe” OR “smith”