±Forensic Focus Partners

Become an advertising partner

±Your Account


Forgotten password/username?

Site Members:

New Today: 1 Overall: 35514
New Yesterday: 4 Visitors: 202

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

±Latest Webinars

Known.met File eMule P2P- need for good parsers

Computer forensics discussion. Please ensure that your post is not better suited to one of the forums below (if it is, please post it there instead!)
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts

Senior Member

Known.met File eMule P2P- need for good parsers

Post Posted: Oct 14, 16 17:14

Hi Folks,

I have a known.met file from eMule and my goal is to prove what files were added to shared folder manually.

I have parsed known.met file using eMule Met Viewer v1.1.2.0 and I can tell about all the records that were present in eMule. This includes downloaded and uploaded files, however in this software there is no indicator which files were added to upload from elsewhere (Not downloaded by eMule)

I know that within individual record in known.met file record sector offset x28 for 4 bytes is x02x01x00x22 TAG: name of .part file. Part file in my understanding is that a part/chunk stands for a part of the entire file that was created during eMule download. If this does not exist, it would be indicative that the file was added to share manually.

Are here any experts on this, have you ever done it?

Is there any other parser that will look into Known.met file?

Perhaps there are some other ways to prove it, please P.M. me if you do not want reply in general.

Thx. Rolling Eyes  


Re: Known.met File eMule P2P- need for good parsers

Post Posted: Oct 24, 16 16:51

Hi pajkow,

you could give "eMuleTotalParser v." a try. You can find it in the member area of FileShareForensics

Kind regards

- Siggi -  

Page 1 of 1