<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>viaForensics&#187; Computer Forensic and E-Discovery Glossary Archives  &#8211; viaForensics</title>
	<atom:link href="http://viaforensics.com/category/computer-forensic-ediscovery-glossary/feed/" rel="self" type="application/rss+xml" />
	<link>http://viaforensics.com</link>
	<description>innovative digital forensics and e-discovery</description>
	<lastBuildDate>Wed, 10 Mar 2010 02:28:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Legal Technology &#8211; An Employee Leaves, Does Your Data Follow?</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/legal-technology-an-employee-leaves-does-your-data-follow.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/legal-technology-an-employee-leaves-does-your-data-follow.html#comments</comments>
		<pubDate>Mon, 09 Nov 2009 15:10:50 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1129</guid>
		<description><![CDATA[
			
				
			
		
Well, I love it when other people write our sales and marketing materials for us.  This is one important component of value in our driveForensics service:
To begin with, there are some inadvertent pitfalls to avoid. The root of the problem is that most HR and IT personnel, while good at what they do, are not [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Flegal-technology-an-employee-leaves-does-your-data-follow.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Flegal-technology-an-employee-leaves-does-your-data-follow.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Well, I love it when other people write our sales and marketing materials for us.  This is one important component of value in our <a href="http://viaforensics.com/corporations" rel="nofollow" title="driveForensics" >driveForensics </a>service:</p>
<blockquote><p>To begin with, there are some inadvertent pitfalls to avoid. The root of the problem is that most HR and IT personnel, while good at what they do, are not trained in computer forensics and the steps necessary to build a case through computer evidence. Oftentimes, building a case against a former employee rests on proving that he or she copied or deleted certain confidential company information. An overzealous company representative trying to find evidence of misconduct can actually do more harm than good, including inadvertently altering the evidence.</p></blockquote>
<p>via <a href="http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202435265910&amp;An_Employee_Leaves_Does_Your_Data_Follow" rel="nofollow" >Legal Technology &#8211; An Employee Leaves, Does Your Data Follow?</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Flegal-technology-an-employee-leaves-does-your-data-follow.html&amp;linkname=Legal%20Technology%20%26%238211%3B%20An%20Employee%20Leaves%2C%20Does%20Your%20Data%20Follow%3F"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/legal-technology-an-employee-leaves-does-your-data-follow.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Rough Economy Has Some Employees Are Daylighting To Make Ends Meet &#8211; KTVI</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/the-rough-economy-has-some-employees-are-daylighting-to-make-ends-meet-ktvi.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/the-rough-economy-has-some-employees-are-daylighting-to-make-ends-meet-ktvi.html#comments</comments>
		<pubDate>Wed, 22 Jul 2009 18:23:24 +0000</pubDate>
		<dc:creator>forensicsadvisor</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://viaforensics.com/?p=1021</guid>
		<description><![CDATA[
			
				
			
		
&#8220;Are my employees Daylighting?&#8221;
&#8220;viaFORENSICS can help you answer this question and a  much…much… more using powerful digital forensic tools that produce court  defensible results…&#8221;
Contact us today to learn more…  sales@viaforensics.com
The Rough Economy Has Some Employees Are Daylighting To Make Ends Meet &#8211; KTVI.

]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fthe-rough-economy-has-some-employees-are-daylighting-to-make-ends-meet-ktvi.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fthe-rough-economy-has-some-employees-are-daylighting-to-make-ends-meet-ktvi.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>&#8220;Are my employees Daylighting?&#8221;</strong></p>
<p>&#8220;viaFORENSICS can help you answer this question and a  much…much… more using powerful digital forensic tools that produce court  defensible results…&#8221;<br />
Contact us today to learn more…  sales@viaforensics.com</p>
<p><a href="http://www.fox2now.com/news/contact2/ktvi-daylighting-070809,0,7625433,print.story" rel="nofollow" >The Rough Economy Has Some Employees Are Daylighting To Make Ends Meet &#8211; KTVI</a>.</p>
<p class="q-details">
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fthe-rough-economy-has-some-employees-are-daylighting-to-make-ends-meet-ktvi.html&amp;linkname=The%20Rough%20Economy%20Has%20Some%20Employees%20Are%20Daylighting%20To%20Make%20Ends%20Meet%20%26%238211%3B%20KTVI"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/the-rough-economy-has-some-employees-are-daylighting-to-make-ends-meet-ktvi.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ADP1</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-adp1.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-adp1.html#comments</comments>
		<pubDate>Thu, 19 Feb 2009 17:38:22 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Andriod Forensics]]></category>
		<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=536</guid>
		<description><![CDATA[
			
				
			
		
The Android Developer Phone (ADP or ADP1) is a version of the G1/HTC Dream for developers and engineers.  Some differences from the retail version include a slightly different look and feel, root access, unlokced SIM and an special bootloader (to name a few).  Here is a nice write up (with pictures) on the ADP1.
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-adp1.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-adp1.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>The Android Developer Phone (ADP or ADP1) is a version of the G1/HTC Dream for developers and engineers.  Some differences from the retail version include a slightly different look and feel, root access, unlokced SIM and an special bootloader (to name a few).  Here is a <a href="http://www.gotontheinter.net/content/android-developer-phone-1" rel="nofollow" title="The Android Developer Phone 1 - JesusFreke"  target="_blank">nice write up (with pictures) on the ADP1</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-adp1.html&amp;linkname=ADP1"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-adp1.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IMSI</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-imsi.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-imsi.html#comments</comments>
		<pubDate>Sun, 15 Feb 2009 20:38:47 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=519</guid>
		<description><![CDATA[
			
				
			
		
The International Mobile Subscriber Identity (IMSI) is an 18-20 digit number uniquely identifying each SIM card.  The information can be used to identify, track or clone a subscriber and is sent as rarely as possible.  Instead,  a randomly generated Temporary Mobile Subscriber Identity (TMSI) is used whenever possible.
The first 3 digits of the IMSI represent [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-imsi.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-imsi.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>The International Mobile Subscriber Identity (IMSI) is an 18-20 digit number uniquely identifying each SIM card.  The information can be used to identify, track or clone a subscriber and is sent as rarely as possible.  Instead,  a randomly generated Temporary Mobile Subscriber Identity (TMSI) is used whenever possible.</p>
<p>The first 3 digits of the IMSI represent the Mobile Country Code followed by 2-3 digits for the Mobile Network Code.  The remaining digits are the Mobile Station Identification Number (MSIN) assigned by the network provider.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-imsi.html&amp;linkname=IMSI"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-imsi.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SWGDE</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-swgde.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-swgde.html#comments</comments>
		<pubDate>Sun, 15 Feb 2009 12:46:11 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=516</guid>
		<description><![CDATA[
			
				
			
		
Scientific Working Group on Digital Evidence (SWGDE) is a government and law enforcement only that &#8220;brings together organizations actively engaged in the field of digital and multimedia evidence to foster communication and cooperation as well as ensuring quality and consistency within the forensic community.&#8221;
In their Best Practices for Computer Forensics, they  have a section on [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-swgde.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-swgde.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Scientific Working Group on Digital Evidence (<a href="http://www.swgde.org/index.html" rel="nofollow" title="Scientific Working Group on Digital Evidence"  target="_blank">SWGDE</a>) is a government and law enforcement only that &#8220;brings together organizations actively engaged in the field of digital and multimedia evidence to foster communication and cooperation as well as ensuring quality and consistency within the forensic community.&#8221;</p>
<p>In their <a href="http://www.swgde.org/documents/swgde2006/Best_Practices_for_Computer_Forensics%20July06.pdf" rel="nofollow" title="Best Practices for Computer Forensics - SWGDE"  target="_blank">Best Practices for Computer Forensics</a>, they  have a section on &#8220;Forensic Analysis/Examination of Non-Traditional Computer Technologies&#8221; which I think is important as it addresses situations that ultimately do arise.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-swgde.html&amp;linkname=SWGDE"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-swgde.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IMEI</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-imei.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-imei.html#comments</comments>
		<pubDate>Sat, 07 Feb 2009 20:53:59 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=497</guid>
		<description><![CDATA[
			
				
			
		
International Mobile Equipment Identifier (IMEI) is a code uniquely identifying the a GSM cell phone on the network generally  displayed on a phone beneath the battery.  They can have 15 (14 decimal digits plus a check digit) or 16 (IMEISV) digits and encoded in the number are the origin, model, and serial number [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-imei.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-imei.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>International Mobile Equipment Identifier (IMEI) is a code uniquely identifying the a GSM cell phone on the network generally  displayed on a phone beneath the battery.  They can have 15 (14 decimal digits plus a check digit) or 16 (IMEISV) digits and encoded in the number are the origin, model, and serial number of the device.  Devices generally report their IMEI number by typing *#06# on the phone.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-imei.html&amp;linkname=IMEI"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-imei.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>tableau-parm</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/tableauparm.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/tableauparm.html#comments</comments>
		<pubDate>Tue, 13 Jan 2009 22:06:14 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>
		<category><![CDATA[forensic tools]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=422</guid>
		<description><![CDATA[
			
				
			
		
tableau-parm is a utility which runs on Linux for interaction with Tableau&#8217;s forensic write blockers.  If you use Tableau&#8217;s products and don&#8217;t run on Windows, you can use this utility to query information from the write blocker (i.e. hard drive information, HPA, DCO, etc.) and even remove HPA/DCO.  The Windows version of the utility by [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Ftableauparm.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Ftableauparm.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://freshmeat.net/projects/tableau-parm/?branch_id=70531&amp;release_id=258157" rel="nofollow" title="tableau-parm - freshmeat.net"  target="_blank">tableau-parm</a> is a utility which runs on Linux for interaction with <a href="http://www.tableau.com/index.php" rel="nofollow" title="Tableau, LLC."  target="_blank">Tableau&#8217;s forensic write blockers</a>.  If you use Tableau&#8217;s products and don&#8217;t run on Windows, you can use this utility to query information from the write blocker (i.e. hard drive information, HPA, DCO, etc.) and even remove HPA/DCO.  The Windows version of the utility by Tableau is called <a href="http://www.tableau.com/index.php?pageid=products&amp;model=TSW-TDM" rel="nofollow" title="Tableau Disk Monitor - Tableau, LLC."  target="_blank">Tableau Disk Monitor</a>.  If you use their hardware, ensure the firmware is up to date with <a href="http://www.tableau.com/index.php?pageid=products&amp;model=TSW-TFU" rel="nofollow" title="Tableau Firmware Update - Tableau, LLC." >Tableau Firmware Update</a>.</p>
<p><strong>Sample Output</strong></p>
<p>Below is sample out from the T35e connected to a WD SATA hard drive:</p>
<p>wintermute:/home/ahoog# tableau-parm /dev/sdd<br />
## Bridge Information ##<br />
chan_index: 0&#215;00<br />
chan_type: SATA<br />
writes_permitted: FALSE<br />
declare_write_blocked: TRUE<br />
declare_write_errors: TRUE<br />
bridge_serial: 000ECC020035C00F<br />
bridge_vendor: Tableau<br />
bridge_model: T35e<br />
firmware_date: Nov  6 2008<br />
firmware_time: 14:22:38</p>
<p>## Drive Information ##<br />
drive_vendor:<br />
drive_model: WDC WD2500JD-55HBB1<br />
drive_serial:      WD-WCAL73972498<br />
drive_revision: 08.02D08</p>
<p>## Drive HPA/DCO/Security Information ##<br />
security_in_use: FALSE<br />
security_support: TRUE<br />
hpa_in_use: FALSE<br />
hpa_support: TRUE<br />
dco_in_use: FALSE<br />
dco_support: TRUE<br />
drive_capacity: 488397168<br />
hpa_capacity: 488397168<br />
dco_capacity: 488397168</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Ftableauparm.html&amp;linkname=tableau-parm"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/tableauparm.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>exifprobe</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-exifprobe.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-exifprobe.html#comments</comments>
		<pubDate>Mon, 05 Jan 2009 18:59:47 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=405</guid>
		<description><![CDATA[
			
				
			
		
Exifprobe is a utility to read EXIF information from digital image files.  I compiles and runs easily on Linux. From the website:
&#8220;Exifprobe reads image files produced by digital cameras (including several so-called &#8220;raw&#8221; file formats) and reports the structure of the files and the auxilliary data and metadata contained within them. In addition to TIFF, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-exifprobe.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-exifprobe.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.virtual-cafe.com/~dhh/tools.d/exifprobe.d/exifprobe.html" rel="nofollow" title="Exifprobe - Duane H. Hesser"  target="_blank">Exifprobe</a> is a utility to read EXIF information from digital image files.  I compiles and runs easily on Linux. From the website:</p>
<p>&#8220;Exifprobe reads image files produced by digital cameras (including several so-called &#8220;raw&#8221; file formats) and reports the structure of the files and the auxilliary data and metadata contained within them. In addition to TIFF, JPEG, and EXIF, the program understands several formats which may contain &#8220;raw&#8221; camera data, including MRW, CIFF/CRW, JP2/JPEG2000, RAF, and X3F, as well as most most TIFF-derived &#8220;raw&#8221; formats, including DNG, ORF, CR2, NEF, K25/KDC/DCR, and PEF.&#8221;</p>
<p>Sample output is available in our <a href="http://chicago-ediscovery.com/computer-forensic-ediscovery-glossary/what-is-exif.html" rel="nofollow" title="EXIF - Computer Forensic and E-Discovery Glossary"  target="_self">exif</a> definition.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-exifprobe.html&amp;linkname=exifprobe"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-exifprobe.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EXIF</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-exif.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-exif.html#comments</comments>
		<pubDate>Mon, 05 Jan 2009 18:51:48 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=402</guid>
		<description><![CDATA[
			
				
			
		
Exchangeable Image File Format (EXIF) is a standard for storing information (or metadata) with an digital image, generally one from a digital camera.  EXIF can contain valuable information about an image, in some cases it will even store the GPS coordinates of where the picture was taken.
Concerns over verifiability of EXIF data
While EXIF data can [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-exif.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-exif.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Exchangeable Image File Format (EXIF) is a standard for storing information (or metadata) with an digital image, generally one from a digital camera.  EXIF can contain valuable information about an image, in some cases it will even store the GPS coordinates of where the picture was taken.</p>
<p><strong>Concerns over verifiability of EXIF data</strong></p>
<p>While EXIF data can be extremely useful, a forensic analysts must not assume this data is accurate.  This information can be easily manipulated or modified.  For instance, the time on the camera can be easily changed.  Or the GPS device may be inaccurate.  Also, there are widely available programs which will allow you to view and update the EXIF information.  In the easly  iPhone 2.x releases, the GPS data (also known as a geotag, geocode or geolocation)  was missing the degree of seconds, making it impossible to point point the exact location.</p>
<p><strong>Sample output<br />
</strong><br />
For reference, the following is the EXIF information recovered from a .jpg that was carved from a file system:</p>
<p>FileType = JPEG<br />
FileSize = 145653<br />
JPEG.APP0           = @2:16<br />
JPEG.APP0.Version       = 1.1<br />
JPEG.APP0.Units         = &#8216;dots/inch&#8217;<br />
JPEG.APP0.Xdensity      = 96<br />
JPEG.APP0.Ydensity      = 96<br />
JPEG.APP0.XThumbnail    = 0<br />
JPEG.APP0.YThumbnail    = 0<br />
JPEG.APP1           = @20:10454<br />
JPEG.APP1.Ifd0.Make                        = &#8216;Canon&#8217;<br />
JPEG.APP1.Ifd0.Model                       = &#8216;Canon PowerShot SD900&#8242;<br />
JPEG.APP1.Ifd0.Orientation                 = 1 = &#8216;0,0 is top left&#8217;<br />
JPEG.APP1.Ifd0.XResolution                 = 180<br />
JPEG.APP1.Ifd0.YResolution                 = 180<br />
JPEG.APP1.Ifd0.ResolutionUnit              = 2 = &#8216;pixels per inch&#8217;<br />
JPEG.APP1.Ifd0.DateTime                    = &#8216;2008:05:31 09:42:15&#8242;<br />
JPEG.APP1.Ifd0.YCbCrPositioning            = 1 = &#8216;centered&#8217;<br />
JPEG.APP1.Ifd0.TAG_0&#215;1001                  = 3648<br />
JPEG.APP1.Ifd0.TAG_0&#215;1002                  = 2736<br />
JPEG.APP1.Ifd0.ExifIFDPointer              = @308<br />
JPEG.APP1.Ifd0.CustomRendered              = 0 = &#8216;Normal&#8217;<br />
JPEG.APP1.Ifd0.ExposureMode                = 0 = &#8216;Auto&#8217;<br />
JPEG.APP1.Ifd0.WhiteBalance                = 0 = &#8216;Auto&#8217;<br />
JPEG.APP1.Ifd0.DigitalZoomRatio            = 1<br />
JPEG.APP1.Ifd0.SceneCaptureType            = 0 = &#8216;Standard&#8217;<br />
JPEG.APP1.Ifd0.Exif.ExposureTime                = 0.00625 sec<br />
JPEG.APP1.Ifd0.Exif.FNumber                     = 8 APEX = &#8216;f16.0&#8242;<br />
JPEG.APP1.Ifd0.Exif.Version                     = &#8216;0220&#8242;<br />
JPEG.APP1.Ifd0.Exif.DateTimeOriginal            = &#8216;2008:05:31 09:42:15&#8242;<br />
JPEG.APP1.Ifd0.Exif.DateTimeDigitized           = &#8216;2008:05:31 09:42:15&#8242;<br />
JPEG.APP1.Ifd0.Exif.ComponentsConfiguration     = 1,2,3,0 = &#8216;YCbCr&#8217;<br />
JPEG.APP1.Ifd0.Exif.CompressedBitsPerPixel      = 5<br />
JPEG.APP1.Ifd0.Exif.ShutterSpeedValue           = 7.3125 APEX = &#8216;0.00629098 sec&#8217;JPEG.APP1.Ifd0.Exif.ApertureValue               = 6 APEX = &#8216;f8.0&#8242;<br />
JPEG.APP1.Ifd0.Exif.ExposureBiasValue           = 0 APEX<br />
JPEG.APP1.Ifd0.Exif.MaxApertureValue            = 2.96875 APEX = &#8216;f2.8&#8242;<br />
JPEG.APP1.Ifd0.Exif.MeteringMode                = 5 = &#8216;Pattern&#8217;<br />
JPEG.APP1.Ifd0.Exif.Flash                       = 24 = &#8216;no flash &#8211; auto&#8217;<br />
JPEG.APP1.Ifd0.Exif.FocalLength                 = 7.7 mm<br />
JPEG.APP1.Ifd0.Exif.MakerNote                   = @718:2372    # UNDEFINED<br />
JPEG.APP1.Ifd0.Exif.UserComment                 = @3090:264 = &#8221; # CC=&#8217;undefined&#8217;    # UNDEFINED<br />
JPEG.APP1.Ifd0.Exif.FlashPixVersion             = &#8216;0100&#8242;<br />
JPEG.APP1.Ifd0.Exif.ColorSpace                  = 1 = &#8217;sRGB&#8217;<br />
JPEG.APP1.Ifd0.Exif.PixelXDimension             = 3648<br />
JPEG.APP1.Ifd0.Exif.PixelYDimension             = 2736<br />
JPEG.APP1.Ifd0.Exif.FocalPlaneXResolution       = 12710.8<br />
JPEG.APP1.Ifd0.Exif.FocalPlaneYResolution       = 12725.6<br />
JPEG.APP1.Ifd0.Exif.FocalPlaneResolutionUnit    = 2 = &#8216;pixels per inch&#8217;<br />
JPEG.APP1.Ifd0.Exif.SensingMethod               = 2 = &#8216;One-chip color area sensor&#8217;<br />
JPEG.APP1.Ifd0.Exif.FileSource                  = 3 = &#8216;DSC&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.Offset                    = @718<br />
JPEG.APP1.Ifd0.Exif.MakerNote.Length                    = 2372<br />
JPEG.APP1.Ifd0.Exif.MakerNote.Scheme                    = &#8216;Plain IFD&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings            = &#8216;45 entries&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.01_MacroMode               = 3026 = &#8216;undefined&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.02_SelfTimer               = 0 = &#8216;off&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.03_Quality                 = 0 = &#8216;unknown&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.04_FlashMode               = 0 = &#8216;flash did not fire&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.05_ContinuousMode          = 92 = &#8216;undefined&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.06_Unknown                 = 2<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.07_FocusMode               = 0 = &#8216;One Shot AF&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.08_Unknown                 = 5<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.09_Unknown                 = 5<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.10_ImageSize               = 0 = &#8216;Large&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.11_EasyShootMode           = 0 = &#8216;Full Auto&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.12_DigitalZoom             = 4 = &#8216;(2 * ZoomedResBase) / ZoomedResValue**&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.13_Contrast                = 65535 = &#8216;Low&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.14_Saturation              = 1 = &#8216;High&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.15_Sharpness               = 0 = &#8216;Normal&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.16_ISO                     = 0/0 = &#8216;Use Exif ISOSpeedRating&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.17_MeteringMode            = 0 = &#8216;Default&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.18_FocusType               = 0 = &#8216;Manual&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.19_AFPositionSelected      = 0 = &#8216;undefined&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.20_ExposureMode            = 0 = &#8216;Easy Shooting&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.21_Unknown                 = 15<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.22_LensType                = 3<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.23_FocalLength_long        = 1 units<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.24_FocalLength_short       = 16390 units<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.25_FocalUnits*             = 0 unit per mm<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.26_Unknown                 = 32767<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.27_Unknown                 = 65535<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.28_FlashActivity           = 0&#215;5a3c = &#8216;undefined&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.29_FlashDetails            = 0&#215;1e14 = &#8216;external E-TTL,Internal flash**,2nd-curtain sync used,FP sync enabled&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.30_Unknown                 = 1000<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.31_Unknown                 = 95<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.32_FocusMode               = 192 = &#8216;undefined&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.33_undefined               = 0xffff/65535<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.34_undefined               = 0/0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.35_undefined               = 0/0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.36_ZoomedResValue**        = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.37_ZoomedResBase**         = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.38_undefined               = 0/0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.39_undefined               = 0xffff/65535<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.40_undefined               = 0/0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.41_undefined               = 0xe40/3648<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.42_ColorTone**             = 0xe40/3648<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.43_undefined               = 0/0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.44_undefined               = 0/0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.CameraSettings.45_undefined               = 0xffff/65535<br />
JPEG.APP1.Ifd0.Exif.MakerNote.FocusInfo                 = &#8216;4 entries&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.FocusInfo.00_unknown                = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.FocusInfo.01_FocalLength            = 32767<br />
JPEG.APP1.Ifd0.Exif.MakerNote.FocusInfo.02_FocalPlaneXSize        = 32767<br />
JPEG.APP1.Ifd0.Exif.MakerNote.FocusInfo.03_FocalPlaneYSize        = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0003                = 0,2,7700,294<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo                  = &#8216;33 entries&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.01_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.02_ISO                          = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.03_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.04_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.05_Unknown                      = 0&#215;4468<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.06_ExposureCompensation**       = 65523<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.07_WhiteBalance                 = 160 = &#8216;undefined&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.08_Unknown                      = 0&#215;125293<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.09_SequenceNumber               = 192<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.10_Unknown                      = 0xea234JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.11_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.12_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.13_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.14_AFPositionUsed               = 0 = &#8216;MF&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.15_FlashBias                    = 0 = &#8216;0 EV&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.16_AutoExposureBracketing**     = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.17_AEBracketValue**             = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.18_Unknown                      = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.19_FocusDistanceMax**           = 0 mm<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.20_FocusDistanceMin**           = 0 mm<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.21_ApertureValue**              = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.22_ExposureTime**               = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.23_Undefined                    = 0&#215;11<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.24_BulbDuration**               = 73<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.25_Undefined                    = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.26_Undefined                    = 0xb9185JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.27_AutoRotate**                 = 231<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.28_Undefined                    = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.29_SelfTimer2**                 = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.30_Undefined                    = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.31_Undefined                    = 0xfa250JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.32_Undefined                    = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ShotInfo.33_Undefined                    = 00<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_000000                = 0,0,0,0,0,0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ImageType                 = &#8221;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.FirmwareVersion           = &#8216;EG&#8217;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.ImageNumber               = 1003599<br />
JPEG.APP1.Ifd0.Exif.MakerNote.OwnerName                 = &#8216;on 1.00&#8242;<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X000D                = 0,0,24313856 &#8230; ,2031616 (148)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0010                = 25755648<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_000000                = 0,9,0,770,11057 &#8230; ,0 (19)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0026                = 0,0,0,0,0 &#8230; ,41 (48)JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0013                = 41,16,0,0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0018                = 04,00,00,00,00,00,00,00,00,00 &#8230; ,00 (256)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0019                = 1<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X001C                = 0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X001D                = 0,0,0,0,0 &#8230; ,0 (16)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X001E                = 16777984<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X001F                = 0,0,0,0,0 &#8230; ,0 (69)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0022                = 0,0,0,0,0 &#8230; ,0 (208)JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0023                = 0,0<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0024                = 0,8,0,0,0 &#8230; ,0 (78)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0025                = 00,00,00,00,00,00,00,00,00,00 &#8230; ,00 (14)<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0027                = 0,4<br />
JPEG.APP1.Ifd0.Exif.MakerNote.TAG_0X0028                = 00,00,00,00,00,00,00,00,00,00 &#8230; ,df (16)<br />
JPEG.APP1.Ifd1.Compression                 = 6 = &#8216;Exif/old JPEG&#8217;<br />
JPEG.APP1.Ifd1.XResolution                 = 180<br />
JPEG.APP1.Ifd1.YResolution                 = 180<br />
JPEG.APP1.Ifd1.ResolutionUnit              = 2 = &#8216;pixels per inch&#8217;<br />
JPEG.APP1.Ifd1.JPEGInterchangeFormat       = @3464<br />
JPEG.APP1.Ifd1.JPEGInterchangeFormatLength = 7012<br />
# Start of JPEG baseline DCT compressed primary image [985x739&lt;=3648x2736] length 145653 at offset 0/0<br />
#   End of JPEG primary image data at offset 0&#215;238f4/145652<br />
# Start of JPEG baseline DCT compressed reduced-resolution image [160x120] length 7012 (IFD 1) at offset 0xd88/3464<br />
#   End of JPEG reduced-resolution image data at offset 0&#215;28eb/10475<br />
NumberOfImages = 2<br />
FileFormat = JPEG/APP0/JFIF/APP1/TIFF/EXIF # with MakerNote (Canon [1])</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-exif.html&amp;linkname=EXIF"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-exif.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scalpel</title>
		<link>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-scalpel.html</link>
		<comments>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-scalpel.html#comments</comments>
		<pubDate>Mon, 05 Jan 2009 15:52:56 +0000</pubDate>
		<dc:creator>ahoog</dc:creator>
				<category><![CDATA[Computer Forensic and E-Discovery Glossary]]></category>
		<category><![CDATA[forensic tools]]></category>

		<guid isPermaLink="false">http://chicago-ediscovery.com/?p=399</guid>
		<description><![CDATA[
			
				
			
		
Scalpel is an open source file carving utility like foremost but with an emphasis on speed and efficiency.  When analyzing a 15GB dd image, scalpel took just under 2 minutes while foremost took nearly 15 minutes.  Foremost carved more files however most were invalid (this is anecdotal and may not always be the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-scalpel.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-scalpel.html&amp;source=ahoog&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.digitalforensicssolutions.com/Scalpel/" rel="nofollow" title="Scalpel - Digital Forensic Solutions"  target="_blank">Scalpel</a> is an open source file carving utility like <a href="http://chicago-ediscovery.com/computer-forensic-ediscovery-glossary/what-is-foremost.html" rel="nofollow" title="What is foremost - Computer Forensic and E-Discovery Glossary"  target="_self">foremost</a> but with an emphasis on speed and efficiency.  When analyzing a 15GB dd image, scalpel took just under 2 minutes while foremost took nearly 15 minutes.  Foremost carved more files however most were invalid (this is anecdotal and may not always be the case!).  Here is the full description from the scalpel website:</p>
<p>&#8220;Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions. It is useful for both digital forensics investigation and file recovery. Scalpel resulted from a complete rewrite of foremost 0.69 a popular open source file carver, to enhance performance and decrease memory usage.&#8221;</p>
<p><strong>See also</strong></p>
<ul>
<li><a href="http://chicago-ediscovery.com/computer-forensic-ediscovery-glossary/what-is-foremost.html" rel="nofollow" title="What is foremost? - Computer Forensic and E-Discovery Glossary"  target="_self">Foremost</a></li>
<li><a href="http://chicago-ediscovery.com/computer-forensics/difference-foremost-scalpel.html" rel="nofollow" title="Difference between foremost and scalpel? - Computer Forensic and E-Discovery Glossary"  target="_self">Difference between foremost and scalpel</a></li>
</ul>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fviaforensics.com%2Fcomputer-forensic-ediscovery-glossary%2Fwhat-is-scalpel.html&amp;linkname=Scalpel"><img src="http://viaforensics.com/wpinstall/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://viaforensics.com/computer-forensic-ediscovery-glossary/what-is-scalpel.html/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
