By
•
August 10, 2020
•
Daily Blog
dfir
ese
sunday funday
•
Hello Reader,
It's been awhile! I wish I could tell you what all I've been up too, but needless to say real investigations got so crazy between May-August that I couldn't even find time to blog without losing even more sleep. So let's pick up where we left off with a Sunday Funday! This week we address a database format we are seeing more and more as developers realize what a useful alternative it is to SQLite on a windows system. This week is all about ESE databases!
The Prize:
$100 Amazon Giftcard
And an apperance on the following week's Forensic Lunch! The Rules:
The Challenge:
When looking at Extensible Storage Engine (ESE) database artifacts (also known as 'Jet Blue' or .edb file):
1. Recover deleted messages from an ESE database from a live database or from the transaction journal.
2. Determine what other applications other than IE, Search Index and SRUM make use of it
3. Determine how to avoid data loss when copying it from a live system