OLK File Forensics – Examine OLK14 File and Export Evidence

MailXaminer | May 18th, 2020 | Forensics

Are you having files with .olk extension? Do you want to perform OLK file forensics to examine the data out of it? Then, check out this blog and explore the best approaches to investigate OLK files without any hassle.

Instead of OST and PST, Outlook for Mac stores its archived data in OLM file format. Though Mac Outlook stores data in OLK format by default. However, while archiving the OLK file, it provides the option to save the OLK data in the OLM file format. Moreover, these OLM files can only be read or accessed by the respective email applications. As the data files are stored in the OLK folder that can be solid evidence for investigation purposes. Therefore, these files are generally used by the forensic experts for analysis purposes to carve those artifacts as to smarty investigate the occurred cybercrime.

Overview – OLK File Format

OLK file format was developed by Microsoft, also known as Outlook Address Book File. OLK14 are the email message files that are created by Outlook 2011 Mac client to store email data. OLK14MESSAGE files manage all the important information regarding the headers of emails collected in Outlook Mac 2011. OLK14MESSAGE file does not have the body of emails, instead, it only contains the header of emails. The body of an email is been stored in another OLK file format, i.e. OLK14MSGSOURCE. Along with this, OLK files stores organizational data, addresses, contact information, phone numbers, etc.

Why Unable to Open OLK Files?

There are some reasons, which make OLK files unable to open or execute. Some of the reasons are mentioned below:

Incomplete Installation of Application: This can be due to incomplete installation of the application that supports the OLK file. To resolve the problem, users can re-install the application properly with all the supported files and folders.

Absence of OLK File Description: Another reason can be due to the absence of the description of OLK files in the Windows Registry. If files are having the issue in terms of execution, then accidental or intentional deletion of the OLK file descriptions can be the cause.

Corrupted OLK File: Sometimes, OLK files are not able to open because of corruption. Due to the harmful malware attack, viruses, etc. files get corrupt and may fail to execute.

Insufficient Resource to Open: If your system does not have proper supported files, folders, storage, etc. that helps in loading the files. Then, the OLK file may fail to open.

What is OLK File Forensics?

In a computer crime scene, sometimes suspect accidentally or intentionally delete the evidential data which may help in finding out the facts. During the investigation analysis for Mac Outlook data, forensic experts analyze OLK files to navigate the evidence from the attachment files saved in OLK folders. The suspect can easily delete the emails from Outlook data files, however, the OLK folder is pretty hard to find, which makes the culprit difficult to erase. Therefore, in Outlook forensics, examiners look first at the OLK folders to get all possible data related to Mac Outlook Files.

To examine OLK files, forensic examiners generally use advanced forensics tools like MailXaminer. It helps to easily trace the facts of the crime scene and evidence with perfection in a systematic way.

An Ultimate Solution to Examine OLK File Using MailXaminer

MailXaminer is the best Email Forensic Software used by digital forensic experts to examine the email data in a broadway. The tool has a wide range of advanced features that make the process easy to find the evidence. MailXaminer supports 20+ email file-formats including OLK files. It has a Search-Based Analytics Feature and Powerful Search Mechanism based on algorithms that help to find the data related to the specified keywords mentioned in the search field. The software also has many more features that make it easy for the investigating officers to smartly analyze the huge data.

It is the best way to analyze email files in a secure and risk-free way. The software provides multiple features that are easy to use and give efficient results. It also recovers the deleted data automatically. After the examination process, users can easily export the evidential files into multiple file formats. In the next section, we are going to understand the process of examination of OLK files using MailXaminer software.

Step-by-Step Process to Perform OLK14 File Forensics

Step 1: Add / Scan file into the Software for OLK file forensics

MailXaminer is designed to support 20+ email file formats. To add the file into the software, users first have to select the file format “.olk14Message”. Then, click on the “Browse” button to select the file from the system. One can add multiple files in bulk by providing the CSV file having the file names and location paths.

Add OLK File

Step 2: View OLK Data Files with Attachments

After adding the file, the investigating officers can view the email files by clicking on the “Mails” section. The preview of the data files will clearly show all the files with attachments. From this screen, users can directly select and view the files for analysis purposes.

Preview OLK File

Step 3: Analyze OLK Files Using Multi-Mode Preview Options

The software provides 9+ preview modes for email files that help to investigate officers to examine files. Users can view the data in multiple modes such as Normal Mail, Hex, Properties, Message Header, HTML, Email Hop, MIME, Attachments, and Word Cloud. Each view provides detailed information on the email that might help to fetch the artifacts.

OLK File Forensics

Step 4: Search Specific Data using Powerful Search Mechanism

The software offers advanced search functionality. Users can find suspected data by providing related keywords for the same. It provides various search options such as General Search, Proximity Search, Regular Expression, Stem Search, Fuzzy Search, and Wildcard Search. Besides this, logical operators such as AND, OR, and NOT can also be availed from the software panel to perform a precise search.

Search OLK Data

Step 5: Use Multiple Search Analytics for Data Analysis

Multiple search analytics helps to find the relation and connections between the users and other entities of the data. It provides four features such as Word Cloud, Link Analysis, Timeline Analysis, and Entity Analysis. This analytics function of the software represents the connection between related data in a graphical representation and helps to analyze the emails conveniently.

Word Cloud – Word cloud analysis is used to represent the frequency of words of a particular email message by differ in size and color.

Link Analysis – It helps to find out the connection and relation between multiple emails that are connected to each other.

Timeline Analysis – This analysis feature helps the investigators to analyze the frequency of emails by particular month, year, and date.

Entity Analysis – This analysis has the ability to show the location-oriented words used within the email message along with their frequencies.

Multiple OLK File Forensics Options

Step 6: Export Evidence Report

After the analysis process, the user can easily export the evidence report using the “Export” option. The tool provides multiple export file formats options such as CSV, EML, MSG, HTML, TIFF, PST, PDF, etc. to export the analysis report. Users can save the report at the desired location of the local system.

Export Evidence

Final Words

The OLK files created by Mac Outlook stores the copy of email attachment files and OLK14Message files store the header information of emails. To analyze these files, investigating officers rely on OLK file forensics software. For better analysis, we recommend an email forensic software named MailXaminer. The tool comprises of various advanced features that can help the digital forensic experts to analyze OLK files in a hassle-free way.