• Shopping Cart Shopping Cart
    0Shopping Cart
Digital Detective
  • Home
  • Corporate
    • About Us
      • Executive Team
      • Our Clients
      • Testimonials
    • News and Events
      • Latest News
      • Press Release
    • Legal
      • Privacy Policy
      • Cookie Policy
      • Returns Policy
  • Products
    • Forensic Software
      • NetAnalysis®
      • HstEx®
      • Blade®
    • Downloads
      • Evaluation Request
      • Free Digital Forensic Tools
    • Product Documentation
      • NetAnalysis® Documentation
      • HstEx® Documentation
      • Blade® Documentation
  • Careers
  • Support
    • Knowledge Base
    • Support Portal
    • Digital Forensics Forum
  • Store
    • Forensic Software
    • View Shopping Cart
  • Blog
  • Contact Us
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

AOL PFC EMail Recovery

Advanced Carving, Blade®, Data Recovery, Digital Forensic Software
AOL logo on dark blue background

Introduction

Not so long ago, one email client which increased in popularity (particularly amongst paedophiles) in the United Kingdom was that provided with America Online (AOL).

Email extraction and analysis causes significant problems for digital forensic examiners. Almost all of the forensic software designed for extracting email is tailored for dealing with mail-store files which are intact.  This means that they have not been designed to extract email data from the other areas of a suspect hard drive such as, unallocated clusters, cluster slack, page files, hibernation files and other binary source files.  They have also not been designed to extract data fragments when the mail-store index has been overwritten.

From an evidential point of view, it is likely that a large quantity of email evidence is not being extracted.  In addition, as there is limited documentation available regarding the proprietary binary file structures, there is wide variance in the output from many of the commercial forensic tools currently available.

Recovery of AOL (Personal Filing Cabinet) Email Messages

Digital Detective’s forensic data recovery software Blade® contains a Data Recovery module (with Intelli-Carve® which has been designed to recover AOL email messages from a number of sources.

The AOL Professional Recovery Module has the ability of recovering live and deleted email messages (including attachments) whether directly from a Forensic image (such as an Encase® e01 compressed image) or a physical disk / volume. The output from the software allows the forensic investigator to identify the exact location the data was recovered from.

The carving engine for this Module is the result of numerous years research and development. It was originally released in the Digital Detective product EMLXtract. When this software was released to law enforcement in 2004, it was the first software product to recover AOL email messages from an image or physical/logical device (as opposed to a single PFC File). When compared against other tools, this software recovered more email messages than any other. It works particularly well against corrupted data when many other tools fail to recover anything at all.

The research and development that went into recovering AOL email messages from a forensic image took a considerable amount of time. AOL email messages contain many different elements such as compressed and non-contiguous data blocks. Embedded attachments can be split and have to be stitched back together. When this module was originally designed, the goal was not to recover live and deleted email messages from a Personal Filing Cabinet, but to be able to recover emails from a disk image. This functionality was originally released to Police Forces all around the world as a tool called EMLXtract.

Through research and development, the recovery engine has been enhanced further and is now part of Blade®.

14th September 2010/by Craig Wilson
Tags: AOL, Email Recovery, Intelli-Carve, PFC
Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
You might also like
Email client showing inbox, compose and starring lniks Recovery of AOL PFC (Personal Filing Cabinet) Email Messages

Categories

Recent Posts

  • NetAnalysis® 4: Boost Your Digital Forensics with Advanced Browser Analysis
  • DataDump™ – Data Extractor and Converter
  • DCode™ – The Digital Detective’s Companion Across Time
  • NetAnalysis® v3.8: Enhanced Browser Support for Digital Forensic Investigations
  • NetAnalysis® v3.7 and HstEx® v5.7 Released

Tags

ACPO Alternate Data Stream Android AOL Binary Coded Decimal BOM Browser Evidence Byte Order Mark Change Log Date & Time Decode Dongle Hell Dongles Donor Drive Email Recovery Encode Find Panel Free Good Practice GSM Guidelines Intelli-Carve Internet Explorer iOS Legal Licensing Linux macOS Network Byte Order News NTFS PFC Preferences Prefs PrivacIE Release Notes Seagate Search Symbolic Links Syntax Timestamp Timestamps Tools Tutorial Zone.Identifier

About US

Digital Detective enhances digital forensic science though cutting edge research and development. We offer a range of products and services for digital forensic analysis and advanced data recovery.

Product tags

Browser Forensics Cached Page Rebuilding Data Recovery Deleted Data Extraction Deleted Data Recovery Digital Forensic Software Product Bundles SMS Upgrade Web Browser Analysis Web Browser Forensics

Select Language

Translate our site by selecting your language from the option below.

Contact Us

Digital Detective Group
Motis Business Centre
Cheriton High Street
Folkestone
KENT, CT19 4QJ
United Kingdom

///courts.endearing.bulbs
+44 (0) 20 3384 3587

© Copyright - Digital Detective - Enfold Theme by Kriesi
  • Link to Facebook
  • Link to X
  • Link to Youtube
  • Link to Mail
  • Home
  • Sitemap
  • Corporate
  • Products
  • Store
  • Blog
  • Contact
Scroll to top Scroll to top Scroll to top