Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


May 08, 2008

"F" Is for Forensic: Exchange Server Investigations

RSS
Subscribe to Windows IT Pro | See More Exchange Server and Outlook Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Forensics have come a long way. Formerly the domain of medical examiners and police crime labs, we now have all sorts of forensic occupations. Forensic accountants analyze financial records of companies to gather evidence of crime; forensic engineers recreate situations such as bridge collapses to figure out what happened. Forensics have become a mainstay of popular culture, leading to widespread public familiarity with some aspects of forensic science. Law enforcement professionals have a phrase for this phenomenon, "the CSI effect," referring to the tendency of amateurs to have inappropriately high expectations for crime solving because of what they see on TV shows such as the popular CSI: Crime Scene Investigation.

Sadly, the CSI effect is alive and well when it comes to Exchange Server organizations. There are several common circumstances where Exchange data collection might be required, such as recovering mailbox data of users who have left a company, performing internal investigations, and capturing data pursuant to subpoenas or other legal demands. These circumstances each have somewhat different characteristics:

  • If you're recovering a former employee's mailbox, your interest is typically just in getting the mail data; metadata such as read/unread status isn't as important, and there's usually no legal requirement to preserve a chain of custody.
  • For internal company investigations, the goal is usually to copy some data from a target mailbox without the target becoming aware of it. Sometimes you need a way to search multiple mailboxes and export the results, again without tipping off the targets or changing any data.
  • For responding to subpoenas or other legal or regulatory demands, you typically need a way to gather all the requested data without altering anything, as well as proving that you retrieved all the data you were asked for. These requests frequently require cross-mailbox searching.

Interestingly, the most commonly used Exchange forensic tool is (drum roll, please) the venerable Exchange Server Mailbox Merge Wizard, commonly known as ExMerge. This utility has the virtue of being very well understood in the Exchange community, and it provides a fairly robust way to move mailbox data and metadata into a PST file. Its logging options are adequate, provided you increase logging above the default level. It doesn't offer any way to search mailboxes, though, which makes it hard to be sure you’ve captured all the content required for your collection.

The Exchange Server 2007 Move-Mailbox cmdlet through Exchange Management Shell solves the search problem by offering a way to search multiple mailboxes for content, then extract matching messages to a PST file. This method solves the most common problems of the three cases listed above. As a bonus, Move-Mailbox is both faster and more robust than the ExMerge engine, and you can use it even if you don't have any Exchange 2007 servers deployed. To do so, you need to install the Exchange 2007 management tools on a workstation (not on your Exchange 2003 servers!) with the Exchange 2007 prerequisites, including Windows PowerShell 1.0 and the .NET Framework 2.0.

The larger question is what best practices are appropriate for performing forensic collections on Exchange servers. There are lots of best practices for conventional forensic data recoveries using tools such as Guidance Software's EnCase eDiscovery. However, many Exchange administrators don't know the common rules of computer forensics, and many of the people who do know those rules don't know much about Exchange. I'm interested in hearing what has, and hasn't, worked well for you during forensic collections—drop me a note at probichaux@windowsITpro.com to let me know, and I'll summarize the results in a future column.

 

End of Article



Reader Comments
This article is useless for "real world' email recovery and discovery in an enterprise setting for forensic purposes.
In the real world you would need to recover individual mailboxes in .PST format from numerous backups of the Exchange Database going back many years and then use discovery tools to search on specific criteria, for example "Enron", "Jeffrey Skilling", "Arthur Anderson", "etc...".
There are numerous tools on the market that are used for this specific purpose and believe, I was hoping to see the "Pros", "Cons" specific to these tools at least mentioned in your article.
Good article for the novice who wants to recover an email from last week, but won't help anyone who is serious about retrieving sensitive email for any real investigation.

calbert_1999 May 10, 2008 (Article Rating: )


In cases that require "enterprise setting" forensic recoveries, 99% of the customers I've encountered go to an outside firm with specialized expertise and tools. My goal wasn't to teach anyone how to conduct these very complex, and legally fraught, operations ab initio. Sorry you took it that way.

The last paragraph is really the most important one in the column because there are so few standards on what constitutes a forensically acceptable collection. For example, compare what your average forensic investigator knows about, looks at, and expects from logs from a disk copy vs. e-mail collection logs.

paulrobichaux May 12, 2008 (Article Rating: )


A new way to promote a good digital chain of custody is to <a href="http://hack-igations.blogspot.com/2008/04/text-message-investigations.html">authenticate records with a voice signature</a>. A voice signature can help show who collected the evidence, when it was collected, and that it has not changed since collection. --Ben http://hack-igations.blogspot.com/2008/04/text-message-investigations.html

benjaminwright May 12, 2008 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

The Desktop tab is missing from the Display Properties in Windows XP?

...


Related Articles SaaS, Email Archiving, and a Free Live Webcast

Symantec's New Evidence Collection and Transfer Tools

LiveOffice, MessageGate Surveys Stress Importance of Preparing for e-Discovery

Develop an Exchange Compliance Strategy

Exchange Server and Outlook Whitepapers Anonymizers – The Latest Threat to Your Web Security

Replay for Exchange: Enterprise Protection and an Affordable Price

ETX Driving Embedded I/O

Related Events Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.
Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Increase Application Performance
Free White Paper by Editor's Best winner, Texas Memory Systems.

Need to convert between XML, DBs, EDI, and Excel? Try MapForce free!
Drag & drop to transform between popular data formats – get results instantly or generate code.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16 in London.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing