Forensic Stance for ScanPST.exe Strategy and Functionality
A digital forensics examiner interrogates several desktop emailing clients while investigation. MS Outlook which is the most commonly used email client for personal as well as corporate usage, is one of the email clients which is investigated frequently. For MS Outlook email applications, reconstruction of PST files is a prime step taken. This reconstruction of PST file is done under many situations where Outlook emails are not accessible or has some part malfunctioned due to which the Outlook messages are not viewable. Inbox repair tool well known as Scanpst.exe which comes with MS Office has functionality to repair Outlook storage file i.e. PST file.
ScanPST.exe – Location Details
ScanPST.exe utility is a file which comes along with the Microsoft office suite for the repairing of MS Outlook storage file. This application helps to rebuild the messages and folders of PST file. This comes as executable file which is generally hidden from the system; investigators can find this application from below mentioned locations;
Steps Involved for Repairing PST File using Scanpst.exe
- Double-click on ScanPST.exe following the location mentioned in the table above.
- Click on Browse option and provide the location of Outlook PST file which has to be analyzed. Once the file is added, click on Start.
- Once the file is added, checking of the file consistency is started. This will check the whole file if any inconsistency occurs through the file, errors are reported.
- If errors are found, it is reported and suggested to repair the file. An option is provided to save a backup file of the scanned PST file. Check the option of “Make backup of scanned file”, click on Browse and provide a name for this backup.
Outcome: The result of this ScanPST.exe is a rebuilt PST file saved on the same location along with .bak file as a backup of the PST file.
Plights Associated with ScanPST.exe!
The performance of ScanPST.exe however is restricted towards minor corruption levels and it works on only low-level objects. To be honest, ScanPST.exe’s checking is restricted towards tables and folder alignment which makes sure whether all the rows in table or message in the folder is available or not. PST which acts as database with BTrees and reference counts can have several other issues which can affect the functionality of emails at front end. If the issue is with low level objects, ScanPST.exe works perfectly fine but if the problem is with upper-level objects, it will not be able to repair the blocks in PST file.
Another predicament in front of investigators is that ScanPST.exe utility has this tendency of removing complete table or block if any data is not readable or corrupted. So there are chances that any email item which was import evident is completely removed due to processing Scanpst.exe on the file. It is always suggested to make a copy of PST file and only then run this Inbox Repair utility. Scanpst.exe utility processes the PST file data and rebuilds it into PST file which can be accessed using MS Outlook application for further analysis but works only with primary corruption in PST file.