|
Products
|
 |
 |
 |
 |
 |
 |
 |
|
 |
Taking Down a Network E-mail Archive Isn't an Option
Whether the evidence you're looking for is in a network e-mail store or a local
e-mail archive, it's not likely you'll be able to acquire that data by taking down
the e-mail if it's on a live network. You'll need to be able to acquire it or analyze it while it's running without risk of data loss or corruption. Paraben Enterprise allows you to forensically analyze or acquire e-mail anywhere on your
network while it's live without data corruption or loss of service. The end user(s) won't even know you've investigated their e-mail.
|
 |
|
How it Works
The concept is simple even if the implementation isn't. The biggest challenge digital investigations of network e-mail stores faces is data corruption due to improper acquisitions or backups of archives. Paraben has been dealing with this for many years with its Network E-mail Examiner product. The reason for most of the corruption is backups either simply make a copy of the archive while data is still being constantly written/deleted from it or their attempts to deal with this issue fall short.
P2 Enterprise correctly handles this by saving all changes to the file in virtual memory once an acquisition is started then, after the acquisition completes, writing all the changes to the file. This same concept applies to any file/folder being acquired while the target machine is in use.
|
|
 |
 |
 |
 |
 |
 |
|
|
|