Difference between pages "Email analysis" and "Template:Incident response"

From Forensics Wiki
(Difference between pages)
Jump to: navigation, search
(New page: == Metadata Extraction == * [http://alioth.debian.org/docman/view.php/30390/47/readpst.1.html READPST] converts pst files to mbox format * Philip Guo has written python scripts to "extra...)
 
 
Line 1: Line 1:
== Metadata Extraction ==
+
[[Category:Incident Response]][[:Category:Incident Response|Incident Response]]
 
+
* [http://alioth.debian.org/docman/view.php/30390/47/readpst.1.html READPST] converts pst files to mbox format
+
* Philip Guo has written python scripts to "extract and organize email header information (e.g., senders, recipients, subjects, dates, etc.) from mbox files". his tools are available on his webpage [http://www.stanford.edu/~pgbovine/mbox-analysis.htm here]
+
 
+
== Tools ==
+
 
+
* [http://sneakers.cs.columbia.edu/ids/emt/ Columbia Email Mining Toolkit]
+

Latest revision as of 14:25, 12 January 2014

Incident Response