複雑な調査において、調査員は組織のメールクライアントによって生成された破損したファイル形式からメールデータを抽出するという任務を負います。調査員は、このファイルを広く互換性のあるEML形式に変換し、分析のためにデータに容易にアクセスできるようにするツールを必要としています。また、ツールは、関連するデータのみを選択的に移行するための高度なフィルタリングオプションを備え、様々なメールサーバーやWebベースのプラットフォームへの移行をサポートする必要があります。このタスクに最適なツールはどれでしょうか?
正解:A
According to the CHFI v11 objectives under Email Forensics and Digital Evidence Examination , investigators must be capable of extracting, converting, and analyzing email data stored in proprietary or corrupt formats. Microsoft Outlook commonly stores mailbox data in OST (Offline Storage Table) files, which can become inaccessible or corrupt during incidents such as system crashes, insider attacks, or malware infections.
Kernel for OST to PST is a specialized forensic and eDiscovery tool designed to recover and convert OST files into accessible formats such as PST, EML, MSG, and MBOX . Its ability to export emails into EML format is particularly important in forensic investigations, as EML is widely supported by multiple forensic tools and email analysis platforms. CHFI v11 highlights the importance of using reliable tools that support selective extraction, filtering, and migration , allowing investigators to isolate relevant emails, attachments, headers, and metadata while maintaining evidence integrity.
Additionally, Kernel for OST to PST supports migration to various email servers and web-based platforms
, aligning with CHFI requirements for handling enterprise email evidence across heterogeneous environments.
The other options are unsuitable: Email Checker and ZeroBounce are email validation tools, and EmailSherlock focuses on email address investigation rather than mailbox data extraction.
Therefore, consistent with CHFI v11 best practices for email evidence acquisition and conversion , Kernel for OST to PST is the correct and exam-aligned answer