Forensic Email Collector v3.86 Release Notes

Let’s start the new year with a sweet FEC update where a few greatly-anticipated features have materialized :grin:

Side Note

Speaking of 386—anyone remember the Turbo button?

Growing up, my friend’s computer had one, and mine didn’t—I thought I was missing out on some speed. :rofl:

Deferred PST Creation

FEC has been building its output PSTs progressively since its launch. When we added the post-acquisition VHDX containerization feature to FEC last month, it became clear that having the same option for PST containers could improve the overall workflow, both in terms of fault tolerance and flexibility.

Similar to containerization, you can trigger this option in two ways: during project setup as an automated action that will run at the end of the acquisition…

…or manually as a post-acquisition action:

When you create PSTs post-acquisition, FEC builds a Post-Acquisition PST Export Log that captures the Item ID <> Output EntryID relationships—similar to what you find in FEC’s Downloaded Items Log for progressively-built PSTs.

FEC Projects Switched to Relative Paths

As we started adding post-acquisition actions to FEC such as packaging Drive attachments, we also started planning to switch from absolute item paths to relative paths so that changing the location of an FEC project does not interfere with the post-acquisition tasks.

This came to a head when we released Forensic Email Intelligence. We’ve found that many of our users wanted to be able to import FEC acquisitions into FEI after having moved them to an archive location—which is completely understandable.

I am happy to report that FEC has now switched to relative paths. Containerization, post-acquisition PST exports, resuming acquisitions, Drive attachment packaging, and FEI imports can now be performed on FEC acquisitions after having moved them to different locations. :muscle:t2:

Extended Drive Support (Yet Again!)

It feels like we are making some Drive improvements in just about every FEC release. This time, we’ve added support for additional Drive item types, such as Google Forms and Google Jamboard files.

What you get with Google Forms is particularly neat—FEC exports a ZIP file containing the design of the form (HTML) and the timestamped responses to the form (CSV).

We have also added quite a few advanced Drive options:

You can read about what these options do in our Drive documentation:

:link: Acquiring Google Drive Attachments of Emails

History Record Improvements

FEC now automatically decodes MessageId timestamps while enriching History Records. This should make it easier to determine the timestamps of messages—especially for deleted items. See the “ID Timestamp” data point in the example below.

Example History Record Export (Partial)
------ HISTORY RECORD ID: 674681 ------
   Messages Added:
      ID Timestamp: 2023-01-04T22:57:32.537Z (Decoded from '1857f010979bc2c5')
      ID: 1857f010979bc2c5
      Folder Path: All Mail
      Subject: Don’t miss out! Winter savings on the #1 rated standing desk
      From: UPLIFT Desk <>
      To: <>
      Message-ID: <>
      Date: 2023-01-04 22:55:31Z

------ HISTORY RECORD ID: 674767 ------
   Messages Deleted:
      ID Timestamp: 2022-12-06T01:58:59.017Z (Decoded from '184e5285ec92e701')
      Message ID 184e5285ec92e701 not found.

Inline Search Improvements

Inline Search now supports calendar and contact types. We have also added startdate and enddate fields so that you can filter calendar events by their dates when performing Inline Searches. This should make your life easier when performing filtered Google Calendar acquisitions or M365 calendar acquisitions via EWS.

As usual, there is much more to this update than these highlights. You can find additional details in our changelog below. Download links are :lock: here.

Recent Announcements from Forensic Email Collector