|
Forensic data is served from EnCase to Windows as read-only and can subsequently be further analyzed with common applications such as Windows Explorer, third-party Windows utilities or other analytical tools. This allows evidence to be viewed and analyzed in a format that may be more familiar to non-EnCase users or non-investigators. Included in the EF Pro Suite:
EnCase Virtual File System (VFS)
-
Mounts evidence at the cases, case, device, volume, or folder level as a read-only network share. (It appears as a network share to the local operating system but the share is not available to other users over the network).
-
VFS provides an easy platform for information or evidence review in a read-only state outside of the EnCase environment.
-
Provides an intuitive platform for evidence to be reviewed by case agents/investigators, opposition experts, prosecutors and defense counsel.
-
Files contain the same file system artifacts as contained in EnCase, including all allocated files, deleted files, internal system files as well as alternate data streams and unallocated space.
|
|
EnCase Physical Disk Emulator (PDE)
-
Mounts images of hard drives or CDs as read-only local drives.
-
Enables the use of third party tools on forensic data exposed by EnCase.
-
When using VMware, PDE enables the examiner to boot and interact with the computer in the same state as it was when the evidence was captured.
-
Provides a platform for juries to view digital evidence in a way that they may better understand.
-
Reduces the number of drive restores, saving time and money needed to stock hard drives.
|
|
EnCase Decryption Suite (EDS)
-
Support for Microsoft Encrypting File System (EFS) encrypted files and folders, including domain authenticated accounts.
-
Support for Outlook PST passwords (except Outlook 2003).
-
Enables the automatic decryption and analysis of Windows registry protected storage area for Internet Explorer.
EnCase Training Schedule
|
|

|