How can I print or export the search results of raw disk viewer text search?
Announcement
Collapse
No announcement yet.
Raw Disk Viewer - Export Results of Search
Collapse
X
-
The short answer is no.
The longer answer is that we'll add a right click option in the search dialog to do this. We'll do this for V2.0 of the software, which we are working on now.
Also in some cases you might be able to do the following,
1) Select the range of sectors on the disk that are interesting
2) Right click in the hex view and select, View selection with internal viewer.
3) In the viewer, click on extract strings, then enter in some filter text
4) If the list show what you want you can right click and export the list.
But this won't give the same results as the raw disk search function. So it is a poor work around at best.
-
My reply above was only in the context of the search function for the raw disk viewer. (e.g. a search for a hex string on the raw disk sectors).
For normal document indexing, and searching it is already possible to export the results.
No date for V2.0 as yet. We have only just started development. We'll definitely have some sort of alpha/beta release this year however. Main focus this week and next is a better browsing function for E-Mail archives.
Plus we are working on finalizing a self booting version of OSF.
Comment
-
Thank you David.
I just wanted to underline the need for documentation. During forensic analysis there is always a need to document results. Having the same documenting abilities for different features like Index Search, Raw Disk Search aso would make working easier.
future plans and directions for the product do sound nice.
btw, itīs already osforensics 1.2. hompeage update needed.
best regards
Comment
-
When an item is added to the currently open case, there is the possibility to add some notes for the item.
You can also add external files to the case (e.g. Word Docs), and add notes directly without needing to add a case item. What additional documentation option were you looking for?
> osforensics 1.2. hompeage update needed
Which page? I checked but didn't see anything obviously wrong with the version numbers?
Comment
Comment