<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;feed=atom&amp;action=history</id>
		<title>Digital Evidence Bags - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;action=history"/>
		<updated>2013-05-25T10:17:19Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;diff=1253&amp;oldid=prev</id>
		<title>Uwe Hermann at 17:25, 3 May 2006</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;diff=1253&amp;oldid=prev"/>
				<updated>2006-05-03T17:25:17Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 17:25, 3 May 2006&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The Digital Evidence Bag (DEB) format mimics in a digital environment the&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;Digital Evidence Bag&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' &lt;/ins&gt;(&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;DEB&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;) format mimics in a digital environment the bags, tags and seals used to traditionally wrap evidence.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;bags, tags and seals used to traditionally wrap evidence. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;When a DEB is&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;When a DEB is created three files are generated:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;created three files are generated:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;# A .tag file which is plain text and stores case specific &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;meta data &lt;/del&gt;such and evidence reference identifier, examiner, location, timestamps and tag continuity blocks that record DEB access activity. In addition to this the tag file contains the cryptographic &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;hashes &lt;/del&gt;(seals) that are used &lt;del class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/del&gt;to maintain and assure the integrity of the DEB structure. &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;# A &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;.tag&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' &lt;/ins&gt;file which is &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[&lt;/ins&gt;plain text&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;]] &lt;/ins&gt;and stores case specific &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[metadata]] &lt;/ins&gt;such and evidence reference identifier, examiner, location, timestamps and tag continuity blocks that record DEB access activity. In addition to this the tag file contains the cryptographic &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[hash]]es &lt;/ins&gt;(seals) that are used to maintain and assure the integrity of the DEB structure.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;A &lt;/del&gt;.index file is a plain text file that records device, file or data source &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;meta data&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;# &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;An '''&lt;/ins&gt;.index&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' &lt;/ins&gt;file is a plain text file that records device, file or data source &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;metadata&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;# A .bag file that holds the evidential data e.g. the raw device bit stream, logical files, network packet capture data.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;# A &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''&lt;/ins&gt;.bag&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;''' &lt;/ins&gt;file that holds the evidential data e.g. the raw device bit stream, logical files, network packet capture data.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;[[Category:File Formats]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Uwe Hermann</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;diff=1252&amp;oldid=prev</id>
		<title>Simsong at 20:46, 31 October 2005</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Digital_Evidence_Bags&amp;diff=1252&amp;oldid=prev"/>
				<updated>2005-10-31T20:46:36Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The Digital Evidence Bag (DEB) format mimics in a digital environment the&lt;br /&gt;
bags, tags and seals used to traditionally wrap evidence. &lt;br /&gt;
&lt;br /&gt;
When a DEB is&lt;br /&gt;
created three files are generated:&lt;br /&gt;
&lt;br /&gt;
# A .tag file which is plain text and stores case specific meta data such and evidence reference identifier, examiner, location, timestamps and tag continuity blocks that record DEB access activity. In addition to this the tag file contains the cryptographic hashes (seals) that are used  to maintain and assure the integrity of the DEB structure. &lt;br /&gt;
# A .index file is a plain text file that records device, file or data source meta data.&lt;br /&gt;
# A .bag file that holds the evidential data e.g. the raw device bit stream, logical files, network packet capture data.&lt;/div&gt;</summary>
		<author><name>Simsong</name></author>	</entry>

	</feed>