Skip to content

Different engines produce different results #42

@MarkBaggett

Description

@MarkBaggett

You will get different results when running srum_dump.exe -e pyesedb and its default mode srum_dump.exe -e dissect

Several forensics tools including pyesedb and Nirsofts EseDatabaseView.exe incorrectly report data in fields that are blank. The resolution is to use run srum_dump.exe with its default mode that uses the dissect.ese parser. An excellent explanation with receipts of which one is correct is in this closed ticket on the dissect repo.

fox-it/dissect.esedb#47

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions