|
Q. What information is
required to be able to secure evidence upon completion of a
scan?
A. Case Number & Serial Number
Q. Can multiple cases be
assigned the same case number?
A. No
Q. The serial number is
missing – how do I proceed?
A. Just enter something – “NA”, “Unavailable”, etc.
Q. Must I use the default
evidence folder?
A. No – one can browse to an alternative evidence directory
(provided it already exits).
Q. How do I enter
user-supplied keywords (for text search).
A. Each word or phrase should be entered with a comma
separator
Q. Are user-supplied
keywords case sensitive?
A. No
Q. Does spelling matter?
A. Yes
Q. Can Forensic Examiner
display all files detected?
A. No – However all files detected can be secured to evidence.
Additionally in the “Copy to” window, user has the option to
open the file in the associated application (provided the
application software is installed) before securing to
evidence.
Q. Where can I secure
files to evidence?
A. To the investigators machine’s hard drive, to floppy disks,
to various external storage devices recognized by the Windows
operating system.
Q. What search settings
substantially increase scan time?
A. “MD5” Calculation and unallocated file search.
|