Paraben s P2C 4.4 Release Ntes
Welcme t Paraben s P2C 4.4! Paraben's P2C is a cmprehensive digital frensic analysis tl designed t handle mre data, mre efficiently while keeping t Paraben's P2 Paradigm f specialized fcus f the entire frensic exam prcess. P2C utilizes Paraben's advanced plug-in architecture t create specialized engines that fcus n such things as E-mail, Netwrk E-mail, Chat Lgs, File Srting, Internet file analysis and mre all while increasing the amunt f data that can be prcessed and utilizing resurces thrugh multi-threading and task scheduling. Nt nly is P2C affrdable, it runs effectively with lwer hardware requirements than yu thught pssible. What s New in P2C v.4.4 P2C can be run withut full administratr s rights. Outlk 2016 PST databases are nw supprted. Interface usability and accessibility with htkeys have been imprved. Parsing NTFS flders has been imprved. Pssible prblems with file srting in unallcated space have been fixed. Pssible prblems with munting RAW images have been fixed. Pssible prblems with Data Triage parsing f email databases have been fixed. Pssible prblems with cntent analysis in varius types f evidence have been fixed. Minr interface and perfrmance imprvements have been made. This dcument prvides yu with a list f all P2C rbust features and a full list f key changes in versin 4.4.
P2C Key Features Paraben s P2C v.4.4 has the fllwing key features: Main features: Analyzing f disks and disk images with the mst ppular file systems, indexing, deleted data recvery, searching, and exprting. Analyzing f the mst ppular mail strage frmats: viewing, searching, srting attachments, and exprting. Analyzing f chat databases, registry hive files, OLE streams, archives, Internet brwser data, memry dump files, and mre. Analyzing the existing frensic cntainers, exprting data t them and creating the new nes. General features: Full Windws 10 cmpatibility, including UAC and digital signature by Micrsft Back-end Firebird database fr supprt f massive amunts f data Multi-threading and task scheduling capabilities t prcess mre data in less time Cnvenient plug-in architecture Easy-t-use registratin scheme GUI features: GUI is redesigned and is nw mre sphisticated than ever. File viewers fr ppular file frmats EXIF data viewer fr graphic files including search in EXIF data and adding EXIF data t reprts Special E-mail data viewer fr viewing e-mail messages in different frmats including viewing attachments Special Chat RTF viewer fr viewing chat histry in a cnvenient frmat Extracted text viewer with pssibility f language changing fr viewing results f ptical character recgnitin Cntent analysis result viewer fr viewing whether a file has signs f malware and malware scan reprt Data Triage Integrated Internet Explrer cache parser Adjustable fnt clr and size Plug-ins features: File system plug-ins allw yu t examine lgical and physical disks as well as individual files and flders (lcal, netwrk and stred n CD/DVD) with: FAT12, FAT16, FAT 32, FATX ExtX HFS+ NTFS (including partitin free space and file slack) STFS Supprts disk images frm the mst ppular frensic imaging sftware Paraben's Frensic Replicatr (PFR) Safeback 2-3 EnCase 4-5-6-7 RAW disk images (created in P2 Enterprise, Smart, etc.) Virtual PC Virtual HD image VMware disk image
Supprts memry dump files E-mail plug-in supprts viewing multiple e-mail and netwrk e-mail frmats in a special e-mail data viewer (including supprt fr exprting data t E-mail Examiner, EML [rfc822 cmpliant], Attachments nly, MSG [OLE message], and PST [Outlk] e-mail frmats) Micrsft Exchange 5.0, 5.5, 2000, 2003 SP1, 2007, 2010, 2013 (EDB) Ltus Ntes 4.0, 5.0, 6.0, 7.0, 8.0, 8.5 (ODS 43 and 51), 9.0. Nvell Grup Wise up t 2012 [new] Micrsft Outlk (PST) up t 2016 Micrsft Outlk Express (EML) E-mail Examiner (EMX) AOL The Bat! (3.x and higher) Thunderbird Windws Mail Ggle Takeut strage Eudra Maildir Chat database plug-in supprts many ppular chat clients fr viewing chat database cntents in a cnvenient, clr cded frmat fr easy analysis Yah! Skype ICQ Miranda Hell (Including Thumbnails) Trillian OLE Strage plug-in supprts the parsing and analysis f any OLE strage Archive plug-in supprts many ppular archive types including: zip, jar, xpi, is, chm, cab, msi, ppt, dc, xls, arj, bzip2, cpi, deb, gzip, lzh, msis, rpm, split, tar, z, wim, and 7z. Internet Data plug-in supprts the parsing and analysis f: Mzilla Firefx cache and histry Internet Explrer cache, ckies, and histry Ggle Chrme histry, ckies, aut fill items, keywrds and lgins SQLite plugin supprts parsing and analysis f SQLite databases including: *.db, *.Sqlite, *.Sqlite3, *.sqlitedb, *.db3, and thers. itunes backup plugin supprts iphne, ipad, and ipd Tuch backups created by itunes, including: ios 1.x 9.x nn-encrypted backups ios 3.x 9.x encrypted backups Frensic Cntainer plug-in allws: Creating a new Frensic Cntainer Adding an existing Frensic Cntainer as evidence Parsing the cntent f a Frensic Cntainer as embedded data in the added file system evidence.
DS case plug-in allws parsing and analysis f cases created by Paraben s DS and Paraben s Deplyable DS. Game Cnsle plug-in allws yu t examine images f lgical and physical disks with evidence frm Xbx 360 including: FATX filesystem used by Xbx. STFS filesystem data intended t stre packages created and dwnladed by the Xbx. XDBF databases cntaining gamer prfile data. Keywrd Search plug-in creates a keywrds database fr keywrds search: Perfrm keywrds indexing f any text data Quick keywrds search in indexed data including multiple parameters fr email evidence Malware Scan plug-in allws yu t check if an executable file has the signs f being malware. File srting: Srt e-mail attachments Srt recvered deleted data Analyze file type/file extensin mismatch Optical character recgnitin Deleted data recvery Other features: Hash database features can manage and Filter Out Cmmn Hashes (FOCH) Autmatic detectin f embedded data frm supprted file types (view e-mail archives, chat databases, disk image files, OLE strage, archives, etc. frm the exact place they are stred withut having t add them t yur case separately) Multiple reprting ptins fr cmplete custmizatin (including a special malware reprt) Image Analyzer fr prngraphic image detectin Optical character recgnitin fr images f mst ppular frmats [NEW!] Malware scan fr executable files An encrypted dynamic Frensic Cntainer creatin Rbust advanced searching and filtering ptins including multi-encding supprt Search within e-mail attachments including search by attachments type Search in deleted data, unallcated disk space, file slack, etc. Multi-parameter search fr each type f data. Regular Expressins search. Ability t search fr data withut searching fr its cntents (file name/directry names) Multi selectin f search results fr adding t a Search results reprt. Exprting Exprt any file in its native frmat Exprt multiple files frm different flders/disks/evidence types Exprt files/flders t frensic cntainers. Exprt mail strage cntents t EML, EMX, PST, MHTML, and MSG frmats. Exprt e-mail attachments in their native frmat. Exprt frm search results and bkmarked data including multi-selectin. Batch exprt fr e-mail databases