<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Pinpoint Labs Blog</title>
	<atom:link href="http://www.pinpointlabs.com/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pinpointlabs.com/wordpress</link>
	<description>How to Preserve, Collect, Recover and Filter Electronic Evidence</description>
	<lastBuildDate>Tue, 18 Jan 2011 23:01:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
		<item>
		<title>What is deNISTing?</title>
		<link>http://www.pinpointlabs.com/wordpress/2011/01/05/what-is-denisting/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2011/01/05/what-is-denisting/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 17:10:01 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Definition]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Electronic Discovery Collection]]></category>
		<category><![CDATA[deNISTing]]></category>
		<category><![CDATA[Electronic Discovery Software]]></category>
		<category><![CDATA[ESI Culling]]></category>
		<category><![CDATA[ESI Requirements]]></category>
		<category><![CDATA[NSRL Hashset]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=363</guid>
		<description><![CDATA[Saving clients money on electronic discovery processing is one of the challenges facing attorneys, service bureaus and their clients. Due to the amount of data collected when imaging custodian hard drives the resulting processing and labor costs can be significant and potentially prohibitive. Reduction of 30%+ Through DeNISTing Many firms have discovered that deNISTing is [...]]]></description>
			<content:encoded><![CDATA[<p>Saving clients money on <a title="Electronic Discovery" href="http://www.pinpointlabs.com/wordpress/2010/12/08/e-discovery-collection/" target="_blank">electronic discovery</a> processing is one of the challenges facing attorneys, service bureaus and their clients. Due to the amount of data collected when imaging custodian hard drives the resulting processing and labor costs can be significant and potentially prohibitive.</p>
<p><strong>Reduction of 30%+ Through <a title="deNISTing" href="http://www.pinpointlabs.com/occh.html" target="_blank">DeNISTing</a></strong><br />
Many firms have discovered that deNISTing is a relatively easy way to reduce the overall EED processing costs for <a title="Forensic Image" href="http://www.pinpointlabs.com/wordpress/2009/01/29/what-is-a-forensic-image/" target="_blank">imaged custodian drives</a> by an average of 30%. How do they accomplish this reduction without missing potential evidence? By removing &#8216;known&#8217; files for Microsoft Windows, Linux, Mac OS and other systems the overall production is substantial reduced.</p>
<p>The NIST (National Institute of Standards and Technology) NSRL list contains more than 115 million known files and by using this list to filter custodian hard drives files, prior to EED processing, a significant reduction can be realized.</p>
<p><strong>What Brought on DeNISTing&#8217;s Recent Popularity?</strong><br />
<a title="deNISTing" href="http://www.pinpointlabs.com/occh.html" target="_blank"> &#8216;DeNISTing</a>&#8216; has become a requested service in just the last few years. Until recently there haven&#8217;t been tools available to handle the processing without significantly increasing the turnaround time and investing in expensive computer forensic software.</p>
<p><strong>Pinpoint Labs&#8217; Harvester Software Makes deNISTing a Reality</strong><br />
<a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/occh.html" target="_blank"><strong>Harvester</strong></a> from <a title="Pinpoint Labs" href="http://www.pinpointlabs.com/" target="_blank">Pinpoint Labs</a> is an affordable and easy to use application which leverages the more than 115 million known hash values in the NIST list to filter custodian data and dramatically reduce the costs and processing time associated with imaged hard drives. Harvester can also dedupe while creating a chain of custody and safely copy filtered files while deNISTing. By performing these multiple processes simultaneously,  Pinpoint Harvester reduces <a title="Electronic Discovery" href="http://www.pinpointlabs.com/wordpress/2010/12/08/e-discovery-collection/" target="_blank">electronic discovery</a> processing costs and labor.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2011/01/05/what-is-denisting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ESI Self Collection Drives and Kits</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/21/esi-self-collection-drives-and-kits/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/21/esi-self-collection-drives-and-kits/#comments</comments>
		<pubDate>Tue, 21 Dec 2010 15:05:38 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Collection]]></category>
		<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Electronic Discovery Collection]]></category>
		<category><![CDATA[Legal Hold]]></category>
		<category><![CDATA[Preservation]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[ESI preservation]]></category>
		<category><![CDATA[ESI Self Collection]]></category>
		<category><![CDATA[Self Collection Drives]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=369</guid>
		<description><![CDATA[Electronically Stored Information (ESI) self collection drives and kits have become popular in the last few years because they offer an affordable means of collecting electronic data for a legal matter without the need to hire in expensive forensic experts. This article covers what should be included in an ESI collection drive kit as well [...]]]></description>
			<content:encoded><![CDATA[<p><a title="Electronically Stored Information ESI" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">Electronically Stored Information (ESI)</a> self collection drives and kits have become popular in the last few years because they offer an affordable means of collecting electronic data for a legal matter without the need to hire in expensive forensic experts. This article covers what should be included in an <a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/occh.html" target="_blank">ESI collection drive kit</a> as well as some tips to ensure the collections are completed properly.</p>
<p><strong>ESI Self Collection Tips and Resources</strong></p>
<p>Here are a few tips to help ensure a successful <a title="ESI Self Collection" href="http://www.pinpointlabs.com/occh.html" target="_blank">ESI self collection</a>:</p>
<p>1) <strong>IT Assistance</strong> –Have someone on hand with knowledge of the products, how they work and how to overcome any issues encountered. This could be an individual with the legal department, corporate IT, a forensic computer examiner, or a competent vendor.</p>
<p>2) <strong>Hard Drives</strong> – If the <a title="ESI Self Collection" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/ " target="_blank">ESI self collection</a> drive is being connected directly to a custodian PC or server, take a look at the 2.5 inch enclosed external hard drives that are powered from a USB port. If collecting data across a network, a Network Attached Storage (NAS) device should be considered.</p>
<p>3) <strong>Software</strong> – Require these key features from <a title="active file collection software" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/ " target="_blank">active file collection software</a> (like SafeCopy 2 or Harvester from Pinpoint Labs):</p>
<ol>
<li><strong>Preserves file timestamps and metadata – </strong>Using Windows Explorer to “drag and drop” files does not <a title="Preserve metadata timestamps" href="http://www.pinpointlabs.com/research/preserve_file_timestamps.htm" target="_blank">preserve critical metadata</a> or confirm that the contents were copied exactly.<strong> </strong></li>
<li><strong>Creates electronic chain of custody </strong>– Report(s) containing details of what happened, source and destination hash values, MAC times, where files were copied from/to and results are the audit trail required for defensibility.</li>
<li><strong>Hash verifies files</strong> – Files hashes of the source and destination are verifiable proof of a valid copy.</li>
<li><strong>No local installation</strong> – Ideally the software should run from an external device or from the network without installing anything on the host computer.</li>
<li><strong>Automated job tickets</strong> – Human involvement opens the risk of human error. Products like <a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/ " target="_blank">Harvester </a>from <a href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">Pinpoint Labs</a> include features to automate the process with predefined work tickets.</li>
<li><strong>Filtering (Optional) </strong>– Filtering at the point of collection reduces the cost of processing the collected data. Some of the filters that can be applied at the point of collection are file types/headers, date ranges, folder names, key words, deduplication, and deNISTing.</li>
</ol>
<p>4) <strong>Evidence Bags </strong>– Tamper-proof evidence bags provide additional security and defensibility. The following antistatic bags from Packaging Horizons (<a target="_blank" href="http://www.alertsecurityproducts.com/antistaticsecuritybag/index.shtml">http://www.alertsecurityproducts.com/antistaticsecuritybag/index.shtml</a>) are designed for hard drives.</p>
<p>5) <strong>Paper Chain of Custody</strong> –Most firms are familiar with transferring evidence and have forms already created. Include this form with the drives used in an ESI collection kit.</p>
<p><strong>Larger Collection Alternatives</strong></p>
<p>Putting together <a title="esi self collection kits" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">ESI self collection kits</a> can save money and eliminate delay and additional costs. Harvester from Pinpoint Labs is offered at a flat rate (you own it) or per collection.</p>
<p><strong>Unease with ESI Self Collections</strong></p>
<p>There has been some concern over custodian self collections. Relying on untrained employees to find, and then properly collect the relevant data may present a defensibility problem.  This problem is overcome easily with automation features of data collection software. These features minimize the number of human errors that can occur by minimizing the amount of employee interaction with the collection process.</p>
<p><strong>What you should know</strong></p>
<p><a title="esi self collections" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">ESI self collections </a>and kits are here to stay. They significantly reduce discovery costs, perform targeted collections, and are the modern equivalent of boxing up relevant files. However, it is critical to ensure that the process is defensible by preserving the original content, with the correct process, products, and procedures. Further assistance designing an ESI self collection kit for specific project needs, contact one of the project leaders at <a title="Pinpoint Labs" href="http://www.pinpointlabs.com/" target="_blank">Pinpoint Labs</a>.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/21/esi-self-collection-drives-and-kits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a Hash Value?</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/10/what-is-a-hash-value/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/10/what-is-a-hash-value/#comments</comments>
		<pubDate>Fri, 10 Dec 2010 17:23:21 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Collection]]></category>
		<category><![CDATA[Computer Investigations]]></category>
		<category><![CDATA[Definition]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Preservation]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Checksum]]></category>
		<category><![CDATA[Deduplication]]></category>
		<category><![CDATA[deNISTing]]></category>
		<category><![CDATA[Electronic Discovery Processes]]></category>
		<category><![CDATA[Hash Function]]></category>
		<category><![CDATA[Hash Probability]]></category>
		<category><![CDATA[Hash Value]]></category>
		<category><![CDATA[Hash Verification]]></category>
		<category><![CDATA[MD5 Hash]]></category>
		<category><![CDATA[SHA-256 Hash]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=332</guid>
		<description><![CDATA[A hash value is a result of a calculation (hash algorithm) that can be performed on a string of text, electronic file or entire hard drives contents. The result is also referred to as a checksum, hash code or hashes. Hash values are used to identify and filter duplicate files (i.e. email, attachments, and loose [...]]]></description>
			<content:encoded><![CDATA[<p>A hash value is a result of a calculation (hash algorithm) that can be performed on a string of text, electronic file or entire hard drives contents. The result is also referred to as a checksum, hash code or hashes. Hash values are used to identify and filter duplicate files (i.e. email, attachments, and loose files) from an <span style="text-decoration: underline;"><a title="ESI Collection" href="http://www.pinpointlabs.com/wordpress/2010/12/08/e-discovery-collection/" target="_blank">ESI collection</a></span> or verify that a <span style="text-decoration: underline;"><a title="What is a forensic image" href="http://www.pinpointlabs.com/wordpress/2009/01/29/what-is-a-forensic-image/" target="_blank">forensic image</a></span> or clone was captured successfully.</p>
<p>Each hashing algorithm uses a specific number of bytes to store a “ thumbprint” of the contents. The following is a list of hash values for the same text file. Regardless of the amount of data feed into a specific hash algorithm or checksum it will return the same number of characters. For example, an MD5 hash uses 32 characters for the thumbprint whether it’s a single character in a text file or an entire hard drive.</p>
<p><strong>HASH</strong></p>
<p><strong>MD5: </strong>464668D58274A7840E264E8739884247</p>
<p><strong>SHA-1: </strong>4698215F643BECFF6C6F3D2BF447ACE0C067149E</p>
<p><strong>SHA-256: </strong>F2ADD4D612E23C9B18B0166BBDE1DB839BFB8A376ED01E32FADB03A0D1B720C7</p>
<p><strong>SHA-384:</strong></p>
<p>2707F06FE57800134129D8E10BBE08E2FEB622B76537A7C4295802FBB94755BBEE814B101ED18CC2D0126BD66E5D77B6</p>
<p><strong> </strong></p>
<p><strong>SHA-512:</strong></p>
<p>C526BC709E2C771F9EC039C25965C91EAA3451A8CB43651EA4CD813F338235F495D37891DD25FE456FE2A8CA89457629378BE63FB3A9A5AD54D9E11E4272D60C</p>
<p><strong>RIPEMD-128: </strong>A868B98EAEC84891A7B7BA620EDDE621</p>
<p><strong>TIGER: </strong>F31A22CEED5848E69316649D4BAFBE8F9274DED53E25C02D</p>
<p><strong>PANAMA: </strong>7E703B1798A26A0AF21ECD661CBADB9C72B419455814CA7B82E29EE0C03FA493</p>
<p><strong>CHECKSUM</strong></p>
<p><strong>CRC16: </strong>117C</p>
<p><strong>CRC32: </strong>FA2D47D4</p>
<p><strong>ADLER32: </strong>CF7D65FF</p>
<p>As you can see there are also various length hashes within a family (SHA-1, SHA-256 et.) The most common hash values are MD5, SHA-1 and SHA-256. The longer hash values require more time to calculate and are designed to reduce the probability of a collision.</p>
<p><a href="http://www.pinpointlabs.com/wordpress/wp-content/uploads/2010/12/Hash-Value-Verification1.jpg"><img class="alignnone size-full wp-image-335" title="Hash Value Verification" src="http://www.pinpointlabs.com/wordpress/wp-content/uploads/2010/12/Hash-Value-Verification1.jpg" alt="What is a Hash Value" width="606" height="469" /></a></p>
<p><strong>A few other ways that hash values are used:</strong></p>
<p>-  Verify a downloaded file was created by the publisher (oppose to a virus infected version)</p>
<p>-   Identify and filter files on the NSRL/NIST list (<a title="deNISTing" href="http://www.pinpointlabs.com/research/how_to_denisting_custodian_drives.htm" target="_blank"><span style="text-decoration: underline;">“deNISTing”</span>)</a></p>
<p>-   Locate known contraband (illegal images and videos)</p>
<p><strong>Here are a few reasons why hash values are so widely used as a means to validate and compare content:</strong></p>
<p>1)  Privileged Data – There would be obvious issues storing and providing multiple copies of the contents of a company’s files or entire hard drives data in a database to perform a byte comparison. Not to mention illegal images and videos (child pornography) would have to be stored and used in each system scan. These scenarios are unacceptable.</p>
<p>2)  Speed – Comparing an indexed hash value versus what could be billions or trillions of bytes or source data is much quicker. Optimized hash engines <span style="text-decoration: underline;">(<a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/occh.html" target="_blank">Pinpoint Harvester</a>) </span>can compare thousands of hash values in a second.</p>
<p>3)  Security  – Hashing data is a one way trip. The original data can’t be recreated or reverse engineered from the hash value. This provides additional security that a person can’t determine the source data from the hash.</p>
<p>The argument that data sources could be different and have the same hash value has raised a lot of concern. There are countless threads related to this issue on the litigation support and computer forensic forums. The bottom line is the only way to do an exact comparison of the original data is to store it everywhere you need to deduplicate or verify the information, however, as mentioned about this isn’t a practical alternative.</p>
<p>More complex hashing functions have been introduced (SHA-256, SHA-512 etc.) which will further reduce the likely hood of a collision. It is also worth noting that even in those cases where scientists have created collisions it was a result of exploiting the weaknesses in a specific hash algorithm. The same alterations would not create a collision in a different hashing algorithm.</p>
<p>So, if you still aren’t satisfied with the incredibly remote possibility a collision could happen using a single hash value then the easiest way to implement an extra precaution is to take the time to have your processes calculate hash values from two separate algorithms (i.e. MD5/SHA256) for each item. Unfortunately, most EED applications and forensic imaging tools don’t support this option, especially  in a single pass.</p>
<p><strong>What to Remember</strong></p>
<p>Hash values are a reliable, fast, and a secure way to compare the contents of individual files and media. Whether it’s a single text file containing a phone number or five terabytes of data on a server, calculating hash values are an invaluable process for Deduplication and evidence verification in electronic discovery and computer forensics.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/10/what-is-a-hash-value/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-Discovery Collection</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/08/e-discovery-collection/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/08/e-discovery-collection/#comments</comments>
		<pubDate>Wed, 08 Dec 2010 13:29:09 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Electronic Discovery Collection]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Email Collection]]></category>
		<category><![CDATA[Forensic Preservation]]></category>
		<category><![CDATA[legal hold]]></category>
		<category><![CDATA[Microsoft Outlook]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=294</guid>
		<description><![CDATA[E-Discovery Collections also known as Electronic Evidence Discovery (EED) or Electronic Data Discovery (EDD) can include a review of all the data stored on employee desktop or laptop computers, company servers, camera cards, cell phones, smart phones, GPS devices, digital video recorders, digital answering systems, thumb drives, RAID arrays and any other form of electronic [...]]]></description>
			<content:encoded><![CDATA[<p><strong>E-Discovery Collections also known as Electronic Evidence Discovery (EED) or Electronic Data Discovery (EDD)</strong> can include a review of all the data stored on employee desktop or laptop computers, company servers, camera cards, cell phones, smart phones, GPS devices, digital video recorders, digital answering systems, thumb drives, RAID arrays and any other form of electronic media capable of storing data.</p>
<p><strong>Types of Electronic Discovery Content</strong></p>
<p><strong><em>Employee Work Product</em></strong> – Computer Files are by far the most common arrangement for a forensic <a title="e discovery collection" href="http://www.pinpointlabs.com/occh.html" target="_blank">e-discovery collection</a>. Files (also referred to as <a title="active files" href="http://www.pinpointlabs.com/wordpress/2010/11/30/active-file-collection/" target="_blank">loose files</a> or <a title="active files" href="http://www.pinpointlabs.com/wordpress/2010/11/30/active-file-collection/" target="_blank">active files</a>) are similar to their paper equivalent. They can be copied, moved, and even “shredded”. Work product could include sales reports, QA reports, product or service information, client lists, engineering designs and much more.</p>
<p><strong><em>Employee Correspondence</em></strong><em> </em>- Email has practically replaced letters and interoffice memos. A <a title="forensic e discovery collection" href="http://www.pinpointlabs.com/occh.html" target="_blank">forensic e-discovery collection</a> of correspondence is often a critical piece and can often contain the “smoking gun”. What someone said, to whom, and when are some of the first questions asked in a legal matter. Since emails are a form of documented communication, they comprise highly sought-after data when it comes to legal matters. Emails themselves may be contained in databases, files, or unallocated space.</p>
<p><em>Customer Relations and Accounting Data</em><em> </em>– Customer lists, internal notes, and financial records are also a critical component in forensic e-discovery collection or computer forensic investigations. Properly collecting the live database files that store this information can be a challenge. Single entries in a database often require export to another format in order to be useful or even readable by humans. Most databases include this ability.</p>
<p><strong><em>User Logs</em></strong><em> </em>– Collecting user logs isn&#8217;t always as relevant in an <a title="Forensics E-Discovery Collection" href="http://www.pinpointlabs.com/occh.html" target="_blank">e-discovery collection</a>/review as it is in computer forensics analysis, however, they can be and are worth mentioning. User logs will contain entries about the activities performed on a computer and different user accounts. Attorneys may want to know when emails were sent or received between accounts in case the emails were deleted.  Log entries may require conversion into human-readable form before they can be processed.</p>
<p><strong><em>Raw or Unallocated Data</em></strong><em> </em>– Unless a forensic image of the source data has been requested a forensically sound e-discovery collection will focus on <span style="text-decoration: underline;"><a title="Active File Collection" href="http://www.pinpointlabs.com/wordpress/2010/11/30/active-file-collection/" target="_blank">“active”</a></span> files. However, it is helpful to understand the difference between “unallocated” and “active” data. Raw or unallocated data is data that resides in segments of the storage media (hard drive, camera card, etc) that are not being used by files. This data can contain all or part of files that were once referenced in the file allocation table but were subsequently deleted. Much of this data can even survive a reformatting of the disk itself. Since this data can come from any number of sources that had once been active on the drive, it can make or break a case where it is suspected that deletions may have occurred.</p>
<p><strong>Tools for Forensic E-Discovery Collection</strong></p>
<p>With the exception of unallocated space, tools such as <a title="Pinpoint Labs Harvester" href="http://www.pinpointlabs.com/occh.html" target="_blank">One Click Collect Harvester</a> from <a href="http://www.pinpointlabs.com" target="_blank">Pinpoint Labs</a> have the ability to collect loose files, emails and whole databases with the added benefits of being able to specify key words, date ranges, domains and email addresses among other very useful filters.</p>
<p>Tools for collecting the unallocated space on a drive usually require an experienced forensic examiner in order to get useful interpretations of the data collected. In cases where this is necessary, it is recommended that a <a title="Certified Computer Examiner" href="http://www.pinpointlabs.com/wordpress/about/" target="_blank">certified computer examiner </a>be hired for the collection and analysis of the data.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/08/e-discovery-collection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Much is a Petabyte, Exabyte, or Zettabyte?</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/07/how-much-is-a-petabyte-exabyte-or-zettabyte/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/07/how-much-is-a-petabyte-exabyte-or-zettabyte/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 14:33:23 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Collection]]></category>
		<category><![CDATA[Definition]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Preservation]]></category>
		<category><![CDATA[Data Sizes]]></category>
		<category><![CDATA[ESI Collection]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=277</guid>
		<description><![CDATA[As our electronically stored information (ESI) data universe continues to grow, we are hearing about increasing storage capacities. The size of a project in terabytes (TB &#8211; 1024 Gigabytes) comes up frequently and is often the amount of data that has to be collected, culled or processed on a corporate server. However, now you can purchase [...]]]></description>
			<content:encoded><![CDATA[<p>As our <span style="text-decoration: underline;"><a title="electronically stored information ESI" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">electronically stored information (ESI)</a></span> data universe continues to grow, we are hearing about increasing storage capacities. The size of a project in terabytes (TB &#8211; 1024 Gigabytes) comes up frequently and is often the amount of data that has to be collected, culled or processed on a corporate server. However, now you can purchase a 1TB drive that will fit in a laptop computer.</p>
<p>Have you heard of a job that will reach or exceed a petabyte? If not, you most likely will in the near future and the following will help if you aren&#8217;t familiar with the larger capacities.</p>
<p><strong>Equivalent Storage in Terabytes</strong></p>
<p>Petabyte = 1,024 TB</p>
<p>Exabyte = 1,048,576 TB</p>
<p>Zettabyte = 1,073,741,824 TB</p>
<p>Yottabyte = 1,099,511,627,776 TB</p>
<p>As the size of electronic data at client sites increases so will the need for refined, <span style="text-decoration: underline;"><a title="Targeted ESI Collection" href="http://www.pinpointlabs.com/occh.html" target="_blank">targeted ESI collections</a></span>. Many litigation support and computer forensic professionals have encountered collection jobs that are several terabytes and are provided <span style="text-decoration: underline;"><a title="keyword collection" href="http://www.pinpointlabs.com/occh.html" target="_blank">keyword search terms</a></span> and other criteria to help identify relevant data and decrease the amount being collected, processed and hosted.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/07/how-much-is-a-petabyte-exabyte-or-zettabyte/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Email Collection</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/06/email-collection/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/06/email-collection/#comments</comments>
		<pubDate>Mon, 06 Dec 2010 14:03:51 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Definition]]></category>
		<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Preservation]]></category>
		<category><![CDATA[Custodian]]></category>
		<category><![CDATA[Email Collection]]></category>
		<category><![CDATA[Email Store]]></category>
		<category><![CDATA[ESI preservation]]></category>
		<category><![CDATA[legal hold]]></category>
		<category><![CDATA[Microsoft Outlook]]></category>
		<category><![CDATA[PST Regeneration]]></category>
		<category><![CDATA[Validation]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=257</guid>
		<description><![CDATA[Email Collection refers to the identification and isolation of electronic mail (email) messages that pertain to a specific legal matter in civil litigation cases. What gets collected What is actually being collected during email collections can be one of two things: 1. Files representing the contents of the transmitted email messages themselves (usually in MSG, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Email Collection</strong> refers to the identification and isolation of electronic mail (email) messages that pertain to a specific legal matter in civil litigation cases.</p>
<p><strong>What gets collected</strong></p>
<p>What is actually being collected during email collections can be one of two things:</p>
<p>1. Files representing the contents of the transmitted email messages themselves (usually in MSG, HTML, EML or RTF format).</p>
<p>2. Container (or store) files that hold the contents and data associated with multiple email messages, usually all of the emails for a specific custodian.</p>
<p>Whether files for individual emails or container files are collected depend mostly on the type of email system being used by the custodian. If the custodian is a user of Microsoft Outlook for instance, then either container files or individual email files may be produced. If the custodian is a user of a webmail service, such as Gmail or Yahoo!, then it is likely only individual email files can be collected.</p>
<p><strong>How it&#8217;s done</strong></p>
<p>Software such as <a title="Harvester by Pinpoint Labs" href="http://www.pinpointlabs.com/occh.html">Harvester</a> from <a title="Pinpoint Labs Collection Software" href="http://www.pinpointlabs.com">Pinpoint Labs</a> can search the PST store files produced by Microsoft Outlook and Exchange email systems for individual emails containing specific criteria, such as who sent the email, who received it, when these actions occurred and whether the subject, body, or attachments contain specified key words. It can also produce the result to either individual email files or whole, reconstructed container files, known as <a title="PST regeneration" href="http://www.pinpointlabs.com/occh.html">PST regeneration</a>.</p>
<p>With other email systems, either the whole container file can be copied and sorted through manually, or the individual emails can be manually identified and exported as individual email files.</p>
<p><strong>What to remember</strong></p>
<p>As with any data being collected, the two concepts to remember are preservation and validation.</p>
<p>Preservation refers to keeping the metadata about the individual messages as well as the metadata contained within each of the messages intact so as to maintain their admissibility. <a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/wordpress/2010/12/02/what-is-pst-regeneration/">PST regeneration</a> is especially desirable in this case because it maintains both the email data and the data that linked it to contact data, task list data and other data integrated with these types of email messages.</p>
<p>Validation refers to the policy of insuring, either by hash value comparison (analogous to fingerprints for data) or bit-wise comparison, that the contents of the copy are the same as the contents of the original.</p>
<p>Software such as <a title="Harvester by Pinpoint Labs" href="http://www.pinpointlabs.com/occh.html">Harvester</a> and <a title="SafeCopy 2 by Pinpoint Labs" href="http://www.pinpointlabs.com/sc2.html">SafeCopy 2</a>, both from <a title="Pinpoint Labs Collection Software" href="http://www.pinpointlabs.com">Pinpoint Labs</a>, have built-in preservation and validation systems to certify that both of these conditions are always met.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/06/email-collection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is PST Regeneration?</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/02/what-is-pst-regeneration/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/02/what-is-pst-regeneration/#comments</comments>
		<pubDate>Thu, 02 Dec 2010 20:30:10 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[custodian email]]></category>
		<category><![CDATA[Email Collection]]></category>
		<category><![CDATA[forensic collection]]></category>
		<category><![CDATA[legal hold]]></category>
		<category><![CDATA[Microsoft Outlook]]></category>
		<category><![CDATA[preservation]]></category>
		<category><![CDATA[PST Regeneration]]></category>
		<category><![CDATA[Regenerate PST]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=246</guid>
		<description><![CDATA[PST Regeneration is used during electronic discovery processing or even during an ESI collection.  A Personal Folder File (PST) is a container file created by Microsoft Outlook which stores email messages and other data (i.e. contacts, calendar entries, tasks, to do list etc.) How it’s done Regenerating PSTs refers to the identification, isolation and often [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PST Regeneration" href="http://www.pinpointlabs.com/occh.html" target="_blank">PST Regeneration</a> is used during electronic discovery processing or even during an <a title="ESI Collection" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">ESI collection</a>.  A Personal Folder File (PST) is a container file created by Microsoft Outlook which stores email messages and other data (i.e. contacts, calendar entries, tasks, to do list etc.)</p>
<p><strong>How it’s done</strong></p>
<p><a title="PST Regeneration" href="http://www.pinpointlabs.com/occh.html" target="_blank">Regenerating PST</a>s<span style="text-decoration: underline;"> </span>refers to the identification, isolation and often deduplication of electronic mail (email) messages that pertain to a specific legal matter in civil litigation cases. The filtered email messages are copied to a new “regenerated” PST file. The resulting PST can be considerably smaller than the original and results in the following benefits:</p>
<p>1)      Quicker attorney review</p>
<p>2)      Electronic Discovery processing and hosting cost reduction</p>
<p>3)      Significantly smaller <a title="ESI Collection" href="http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/" target="_blank">ESI collection</a></p>
<p><strong>Practical application</strong></p>
<p><a title="Regenerate PST" href="http://www.pinpointlabs.com/occh.html" target="_blank">PST regeneration</a> is commonly used when there are dozens of archive (backup) PST files that contain many duplicate messages. It is a common practice for companies to set up Microsoft Outlook or Exchange servers to create daily, weekly or monthly PST backups of employee email messages.</p>
<p>The result is potentially dozens of employee backup PST files which contain duplicate messages. Why? Each backup will contain many of the same messages as the last. Only new emails sent or received (that have not been deleted) since the last backup will be considered “unique” to each PST. Regenerating PSTs<strong> </strong>with only one copy of each email (deduplication) significantly reduces the number of messages and the size of the PST data to be processed or produced.</p>
<p><strong>Maintaining defensibility</strong></p>
<p>Significant cost reductions related to electronic discovery processing and hosting are gained by deduping, performing key word, date range, and email/domain filtering on the emails in PST files. However, it is critical to use an application that is designed to regenerate PSTs in a defensible manner and maintains the chain of custody.</p>
<p>Software such as <strong><a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/occh.html" target="_blank">Harvester</a></strong><a title="Pinpoint Harvester" href="http://www.pinpointlabs.com/occh.html" target="_blank"> </a>from <a title="Pinpoint Labs" href="http://www.pinpointlabs.com/" target="_blank">Pinpoint Labs</a> (designed by Certified Computer Examiners (CCE’s)) can regenerate PST files at the point of collection or during in-house processing. Harvester also creates an extensive verification log (chain of custody) for all copied and duplicate messages.</p>
<p><strong>What to remember</strong></p>
<p>Creating deduped, targeted PSTs is common practice in the electronic discovery lifecycle because it saves clients a considerable amount of money as well as reducing attorney review time. <a title="Regenerate PST" href="http://www.pinpointlabs.com/occh.html" target="_blank">PST regeneration</a> may be performed onsite (during an ESI collection) or in-house to cull down responsive data.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/02/what-is-pst-regeneration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is ESI (Electronically Stored Information)?</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/#comments</comments>
		<pubDate>Wed, 01 Dec 2010 14:28:10 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Collection]]></category>
		<category><![CDATA[Definition]]></category>
		<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Preservation]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=239</guid>
		<description><![CDATA[ESI (Electronically Stored Information) is the general term for all of the data stored on the hard drives, camera cards, cell phones, GPS devices, digital video recorders, digital answering systems, thumb drives, RAID arrays and any other form of electronic media capable of storing data. Types of Electronically Stored Information: Files &#8211; Files are by [...]]]></description>
			<content:encoded><![CDATA[<p><strong>ESI (Electronically Stored Information)</strong> is the general term for all of the data stored on the hard drives, camera cards, cell phones, GPS devices, digital video recorders, digital answering systems, thumb drives, RAID arrays and any other form of electronic media capable of storing data.</p>
<p><strong>Types of Electronically Stored Information:</strong></p>
<p><em>Files</em> &#8211; Files are by far the most common arrangement for ESI data. Files (also referred to as <a target="_blank" href="http://www.electronic-discovery-collections.com/2010/11/29/active-file-collection/">loose files</a> or <a target="_blank" href="http://www.electronic-discovery-collections.com/2010/11/29/active-file-collection/">active files</a>) can be thought of as data containers similar to files in the real world. They can be copied, moved, and distributed freely on a variety of different media from DVDs to hard disk drives.</p>
<p><em>Emails </em>- Emails are messages sent from user to another. In their raw form, they are simply a stream of data that contains everything needed to get the message from one user to another user. Since emails are a form of documented communication, they comprise highly sought-after data when it comes to legal matters. Emails themselves may be contained in databases, files, or unallocated space.</p>
<p><em>Database Entries </em>- Database entries is data stored in a database. This type of data is usually context-specific and may be information pertaining to financial records, personnel entries or other data that is interrelated. Single entries in a database require export to another format in order to be useful or even readable by humans. Most databases include this ability.</p>
<p><em>Log Entries</em> &#8211; Log entries are lines in files or entries in databases that contain information about activity on a particular computer. The more commonly useful log entries pertain to users logging into and out of a computer, accessing specific internet sites, the sending or receiving of email or other messages and the moving, copying or accessing of files on the computer. Log entries may require conversion into human-readable form before they can be processed.</p>
<p><em>Raw or Unallocated Data </em>- Raw or unallocated data is data that resides in segments of the storage media (hard drive, camera card, etc) that are not being used by files. This data can contain all or part of files that were once referenced in the file allocation table but were subsequently deleted. It can also contain deleted internet history, old information from the computer&#8217;s RAM (Random Access Memory) or even old configuration data about the computer itself. Much of this data can even survive a reformatting of the disk itself. Since this data can come from any number of sources that had once been active on the drive, it can make or break a case where it is suspected that deletions may have occurred.</p>
<p><strong>Tools for Collecting ESI</strong></p>
<p>With the exception of unallocated space, tools such as <a href="http://www.pinpointlabs.com/occh.html">One Click Collect Harvester</a> from <a href="http://www.pinpointlabs.com">Pinpoint Labs</a> have the ability to collect loose files, emails and whole databases with the added benefits of being able to specify key words, date ranges, domains and email addresses among other very useful filters.</p>
<p>Tools for collecting the unallocated space on a drive usually require an experienced forensic examiner in order to get useful interpretations of the data collected. In cases where this is necessary, it is recommended that a certified examiner be hired for the collection and analysis of the data.</p>
<p><script src="http://server.iad.liveperson.net/hc/31558923/x.js?cmd=file&amp;file=chatScript3&amp;site=31558923&amp;imageUrl=http://www.pinpointlabs.com/images/lc"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/12/01/esi-electronically-stored-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is an Active File Collection?</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/11/30/active-file-collection/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/11/30/active-file-collection/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 16:52:05 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Collection]]></category>
		<category><![CDATA[Definition]]></category>
		<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[ESI Software]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Preservation]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=237</guid>
		<description><![CDATA[Active File Collection refers to the collection of files that are active (not deleted) and pertain to a legal matter or legal hold. In most civil litigation cases, extensive forensic investigations that look at deleted files are unnecessary or too expensive. Thus, most ESI collections are active file collections and/or email collections. How active file [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Active File Collection</strong> refers to the collection of files that are active (not deleted) and pertain to a legal matter or legal hold. In most civil litigation cases, extensive forensic investigations that look at deleted files are unnecessary or too expensive. Thus, most <a target="_blank" href="http://www.electronic-discovery-collections.com/2010/11/24/esi-electronically-stored-information/">ESI collections</a> are active file collections and/or email collections.</p>
<p><strong>How active file collections are performed</strong></p>
<p>Active files are those that can be seen by normal users. They may include hidden or system files, but they do not include the computer&#8217;s Random Access Memory or any deleted files. Files in the Windows Recycle Bin are considered active files and are subject to collection using <a href="http://www.pinpointlabs.com/research/esi_electronic_discovery_collection_software.html">active file collection methods</a>.</p>
<p>The first step is defining which files need to be collected. This definition can range from &#8220;everything&#8221; to files of a few specific types containing only certain key words. Since the cost of processing is usually related to the size of the data being processed, it is generally more economical to be as specific as possible without leaving out relevant files.</p>
<p>Once the files have been identified, it is mostly a matter of copying them in a manner that both avoids spoliation and provides a means of certifying the contents of the copies.</p>
<p><strong>What to remember</strong></p>
<p>The one thing to remember about <a href="http://www.pinpointlabs.com/occh.html">active file collections</a> is that they can be a potential minefield of spoliation. To avoid this, use software that is designed to preserve the metadata, the timestamps, and the data within the copied files. Some products, such as <a href="http://www.pinpointlabs.com/sc2.html">SafeCopy 2</a> from <a href="http://www.pinpointlabs.com">Pinpoint Labs</a> are designed specifically for this purpose. Others, like <a href="http://www.pinpointlabs.com">Harvester</a>, also from <a href="http://www.pinpointlabs.com">Pinpoint Labs</a>, offer this feature as well as the ability to cull data by key word search and also support deduplication, email, and <a href="http://www.pinpointlabs.com/research/how_to_denisting_custodian_drives.htm">deNISTing</a>.</p>
<p>The most important aspects of <a href="http://www.pinpointlabs.com/occh.html">active file collections</a> are preservation and validation.</p>
<p>Preservation refers to the preservation of the file data, its timestamps (when the file was created, last modified, and last accessed), and any other metadata contained within the file. If any of this data is compromised, the usefulness and admissibility of the file comes into question.</p>
<p>Validation refers to the ability to certify that the contents of the copy are the same as the contents of the original. This is usually done using a hash (analogous to a fingerprint of the files data). It may also be done using a bitwise comparison of the data in both the file and the copy, but since this method requires the same amount of storage as the files themselves and offers no means of independent verification, it is not in common use.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/11/30/active-file-collection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ESI (Electronically Stored Information) Software Challenges</title>
		<link>http://www.pinpointlabs.com/wordpress/2010/11/24/esi-software-challenges/</link>
		<comments>http://www.pinpointlabs.com/wordpress/2010/11/24/esi-software-challenges/#comments</comments>
		<pubDate>Wed, 24 Nov 2010 14:30:25 +0000</pubDate>
		<dc:creator>Jon Rowe</dc:creator>
				<category><![CDATA[Computer Investigations]]></category>
		<category><![CDATA[ESI Collection]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[Electronically Stored Information]]></category>
		<category><![CDATA[ESI]]></category>

		<guid isPermaLink="false">http://www.pinpointlabs.com/wordpress/?p=146</guid>
		<description><![CDATA[A couple weeks ago, I outlined what computer forensics and electronic discovery have in common and how they differ. I’d like to expand on this topic by identifying some common obstacles encountered when using popular computer forensic software for typical electronic discovery projects. A typical computer forensic case may involve: A small quantity of email [...]]]></description>
			<content:encoded><![CDATA[<p>A couple weeks ago, I outlined what computer forensics and electronic discovery have in common and how they differ. I’d like to expand on this topic by identifying some common obstacles encountered when using popular computer forensic software for typical electronic discovery projects.</p>
<p>A typical computer forensic case may involve:</p>
<ol>
<li>A small quantity of email and/or attachments</li>
<li>Recovered files, internet history, and user activity</li>
<li>Registry entries</li>
<li>Pre-fetch files</li>
<li>Portions of unallocated space</li>
</ol>
<p>A typical electronic discovery project may involve:</p>
<ol>
<li>Processing dozens or hundreds of custodian mailstores that results in thousands of potentially relevant emails and/or attachments</li>
<li>Indexing hundreds of gigabytes or multiple terabytes of data</li>
<li>Hosting data online so multiple parties can easily review, identify, and produce files</li>
<li>Converting relevant files to tiff, endorse, and build load files compatible with common litigation support applications</li>
<li>Deduping emails, attachments, and files across dozens of custodians</li>
</ol>
<p>Generally speaking, the primary obstacles encountered when using off-the-shelf computer forensic software for electronic discovery are:</p>
<ol>
<li>Inability to create load files from tagged emails, attachments, and other relevant data</li>
<li>No support for tiffing, endorsing, and assigning docIDs</li>
<li>Missing/incomplete links between email and attachments</li>
<li>No clear way to produce carved or partial files recovered from unallocated space</li>
</ol>
<p>If you anticipate reviewing a large ESI collection using one of the common litigation support review tools, make sure that your service provider can process and produce compatible output files for production sets. Don’t assume that all computer forensic examiners are equipped to handle large scale ESI projects.  On the other hand, not all EED service providers have the appropriate tools to complete a thorough computer investigation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinpointlabs.com/wordpress/2010/11/24/esi-software-challenges/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

