Importance Of Encase LX01 File Format In Digital Forensics Investigation

MailXaminer | December 10th, 2018 | Forensics

LX01 is the logical evidence file created by Encase Forensic Software with .lx01 file extension. It allows the users to store the smaller collection evidence file without loading the entire EX01 file. L01 was the previous file format used to save the Encase Logical Evidence File which is replaced by LX01 file format, which offers more advanced security features.

Encase Forensic Software Tool in Digital Forensics

Encase is the Digital Investigation Software by Guidance Software. Which is mainly used for recover evidence from the seized hard drive in Digital Forensic. Encase Software helps the Investigators to extract and analysis the digital image of evidence in Forensics Investigation. Encase create Logical Evidence File (LEF) to store the collected evidence. It allows the experts to save the selected evidence file from the image file without loading the entire disk image. It maintains the exact copy of the file so it helps the experts in court proceedings and for further review of the stored evidence. But the Encase evidence file is not in a human readable format. Encase Software create evidence file in two file formats they are:
EX01: It is the Encase Imaging File Format. Which saves the entire copy of the hard disk by extracting every data including the deleted data by maintaining its integrity and consistency.

LX01: It is the Encase Logical Evidence File. Which store the selected Evidence Without loading the entire image file. It also maintains the consistency and integrity of the collected evidence.

Encase Logical Evidence File LX01

In every Investigation, the first task performed by the investigators is the collection of evidence from various sources and storing it. The storage of collected evidence in suitable file format without having any changes in its consistency and integrity is a very important duty of Investigators. One of such reliable file format to store these evidence is Encase LEF file. Which allow to save the selected artifacts instead of saving the entire image of the evidence for the investigation purposes.

Through this, it allows maintaining the confidentiality of the investigating case by sharing only the required data instead of sharing the entire case evidence during the investigation. Logical Evidence file helps the investigators to understand the various aspects of the case through the detailed analysis of evidence. Encase Logical Evidence File provide the following information.

Digital Image: It creates an accurate image without changing the integrity and consistency of the evidence.

Evidence parameter: Addition to the actual evidence the Encase Logical Evidence File also contains other parameters related to the case to understand the nature and other aspects of the case.

  • Name: Encase LEF file name
  • Case Name: Name of the case to which the Encase file belongs to.
  • Evidence Number: Unique identification number of the evidence.
  • Examiner Name: Name of the examiner who publishes the Encase file
  • Notes: Addition notes related to the case to understand by other investigators.

Encase Logical Evidence File is store in LX01 file format. In Older version Encase create Logical Evidence File in L01 file format and it is replaced by LX01. Because it provides more advanced security features over L01 such as AES256 encryption, LZ compression, and options for SHA1, MD5 hashing. LX01 file extension maintains its data integrity by encrypting the evidence using hashing algorithms and provide the authenticity by locked the encrypted file using the public and private keys.

Purpose of LX01 file type in Digital Forensics

  • LX01 helps to examine the particular evidence from a large amount of data and saves the storage memory.
  • Help Investigators in court proceedings and for further reviews process.
  • Providing advanced security mechanisms such as AES256 encryption, LZ compression etc over L01 file format.
  • Maintain the data without loss or manipulate any important informations.
  • Ensure the integrity of evidence through MD5 and SHA1 hashing algorithms.
  • Provide Authenticity through public and private keys.

Examine LX01 File Format Using MailXaminer

MailXaminer also provides the option for search and analysis the Encase create Logical Evidence File of LX01 and L01 file format. Perform the following steps to search and examine the LX01 file type.

STEP 1: Add the LX01 file

Use Add Evidence option to select LX01 file extension for the further analysis process. Select LEF- processed Emails to add LX01 file.

add lx01 file

STEP 2: Preview Lx01 File Details

After the LX01 file format is scanned click on the search option to search and preview the emails. There you can select either General or Proximity search according to the purposes.

 Preview Lx01 File

Step 3: Advance Search Option in MailXaminer

Use Logical Operators AND, OR, NOT and Search Algorithms such as Wildcard Search, Stem Search, Fuzzy Search, Regular Expression search to perform an advanced search on LX01 File type.

search Lx01 File

STEP 4: Analysis option in MailXaminer

MailXaminer also provides the option for Link Analysis and Timeline Analysis to find the relationship in Email Investigation.

analysis Lx01 File

STEP 5: Export option

After finding the specific evidence lx01 file type, MailXaminer allows you to selectively export the resultant evidence file into various file format like PDF, EML, MSG, HTML etc.

Export result


In Digital Forensics Investigation, recording of the collected evidence is a very important process. Encase Logical Evidence File with LX01 file extension is one of the reliable format which stores the evidence in a selective manner by maintaining its consistency and integrity. To examine Case Details in Encase Lxo1 File use SysTools MailXaminer. An Email Forensic Tool that helps forensic Investigator to search and examine the evidence stored in Encase LX01 file format and save the Forensic report in Different file formats.