Any eDiscovery tool needs to have an inbuilt search mechanism to help the investigators discover smoking guns. The strength of analyzing email artifacts is further emphasized by the powerful and robust Search mechanism of the application. Its search algorithms hits that most of the competitors will miss. All the searches made can be saved for later retrieval. This saves a lot of time for the investigators in case the same search is to be made multiple times. Depending upon the level of sophistication involved in the search exercise, Software categorizes its searches into 4 Levels.
Generic Search working on the Basis of Keywords
"General Search" is basically a generic search used for an overall search in all the scanned files. Users can input a either a single keyword or a list of keywords and can hit the search button to get the results. Keywords mentioned within double quotes, fetch results matching with the exact keyword. The General search can be further be narrowed down to be more specific, by searching for keywords in specific fields like subject, sender, receiver, mail body etc.
PreDedined Search to Identify Particular Patterns
Predefined Search is based on the algorithm of Regular Expressions Search. This search is useful for an investigators when he/she is trying to identify a particular pattern in the email evidences. Various categories supported by the tool include Phone Numbers, Addresses, URLs, Postal Code, Personal Identifiers, Date and Time, Product Keys, etc.
Selecting the category as "URLs" from the dropdown menu and the subcategory as "Internet URLs", gives the results as all the mails having URLs in their header and/or mail body. Similarly searches can be executed based on categories like telephone numbers (UK, USA, India etc.), personal identifiers (Credit Card, ID), postal addresses and so forth.
Sophisticated and Comprehensive Search Mehanism
As the name suggests, Advance Search is the most sophisticated and comprehensive search of all. The Advance search can limit a search to emails with specific words in the header or located in specific categories or namespaces. For all the search results, the email preview pane is available right besides the search results. It gives the preview of the search results in multiple formats.
Proximity Search – A Hit & Trial Method
The "Proximity Search" input two words & asks for providing an approx number (from zero to infinity) of words between those two characters. This search can be executed by the Hit & Trial method. Given example shows the email including maximum upto 4 words between the two input characters: