Format
Logical File Evidence Format
Summary
- Name
- Logical File Evidence Format
- Identifiers
- PUID: fmt/804
- Description
- Logical FIle Evidence Format was introduced in EnCase version 5. They are form of Encase Image files, this format is used to store media images for forensic purposes. They are a type of disk image containing the contents and structure of an entire data storage device, disk volume or even a computer's physical memory. The logical version of this format is used to create an image of the original files as they existed on the media but also documents other ifnormation. This includes the assigned file name and extension, datetime of creation, modified date, and date last accessed, the logical and physical size, an MD5 hash value, permissions and original path. This format creates segments which have different file extensions, the first will have the extension '.l01'. this increases first numerically upto '.l99' the next extension will be '.laa' increasing to an estimated limit of '.zzz'.
- File extensions
-
l01 - Source
- Digital Preservation Department / The National Archives
Internal signatures
L01
- Note
- Header - LVF...ΓΏ.
Byte sequences
- Min Frag Length
- Absolute from BOF
- Offset
- 0
- Max offset
- 0
- Byte Sequence
4C5646090D0AFF00- Endianness
- None
Changelog
-
Added in V83
- Release date
- 17 December 2015
Logical File Evidence Format: Signature developed through PRONOM Research.
Logical File Evidence Format: Full entry added.