Skip to main content
Service phase: Beta

This service is still in development. Give us your feedback or view this page on the current PRONOM service.

Format

Logical File Evidence Format

Summary

Name
Logical File Evidence Format
Identifiers
PUID: fmt/804
Description
Logical FIle Evidence Format was introduced in EnCase version 5. They are form of Encase Image files, this format is used to store media images for forensic purposes. They are a type of disk image containing the contents and structure of an entire data storage device, disk volume or even a computer's physical memory. The logical version of this format is used to create an image of the original files as they existed on the media but also documents other ifnormation. This includes the assigned file name and extension, datetime of creation, modified date, and date last accessed, the logical and physical size, an MD5 hash value, permissions and original path. This format creates segments which have different file extensions, the first will have the extension '.l01'. this increases first numerically upto '.l99' the next extension will be '.laa' increasing to an estimated limit of '.zzz'.
File extensions
l01
Source
Digital Preservation Department / The National Archives

Internal signatures

L01

Note
Header - LVF...ΓΏ.

Byte sequences

Min Frag Length
Absolute from BOF
Offset
0
Max offset
0
Byte Sequence
4C5646090D0AFF00
Endianness
None

Changelog

  • Added in V83

    Release date
    17 December 2015

    Logical File Evidence Format: Signature developed through PRONOM Research.

    Logical File Evidence Format: Full entry added.