Home /

EnCase® Forensic

The industry-standard computer forensic solution. Fast, powerful, and proven in courts.

Buy NowRequest a QuoteContact Me
For more information, speak
with a solution specialist:
1 (888) 999-9712
 
ForensicImager

 

Watch

  • Six Reasons to Upgrade to EnCase
    Forensic v7 Watch Now 
See More Webinars and Demos...
 

Blog

 

Read

 
See More Whitepapers and Briefs...
 

More Info

EnCase App CentralWhat's new in EnCase Forensic v7EnCase Forensic TrainingEnCE CertificationExternal InvestigationsEnCase Academic ProgramEnCase Site License 
  • Overview

    EnCase® Forensic, the industry-standard computer investigation solution, is for forensic practitioners who need to conduct efficient, forensically sound data collection and investigations using a repeatable and defensible process. The proven, powerful, and trusted EnCase® Forensic solution, lets examiners acquire data from a wide variety of devices, unearth potential evidence with disk level forensic analysis, and craft comprehensive reports on their findings, all while maintaining the integrity of their evidence.
     

    EnCase Forensic v7.06:

     
    The Fastest Most Comprehensive 
    Forensic Solution Available 
    The enhanced capabilities in v7.06 will make completing your investigations more efficient than ever before. Automation, speed and processing enhancements are just a few of the upgrades in EnCase Forensic v7.06. Learn more about how you can take your investigations to the next level.

    Learn More...  
    NEW-v705-Professionals-image
     

    The Standard in Computer Forensics
    Keeps Getting Better...

    Learn More

    New EnCase Review Package

    The EnCase Review Package allows forensic examiners to share findings with other involved with a case, including detectives, D.A.s, field agents and other investigators.

    Learn More About EnCase Review Package  

     
     
    Experts Trust EnCase® Forensic:
    • Increase confidence in findings by using the proven, trusted, industry-leading forensic solution
    • Uncover potential evidence using advance searching capabilities
    • Improve efficiency by automating common investigation tasks
    • Preserve evidence integrity with the court vetted EnCase® evidence file format
     
    Dependable-Icon
    Dependable Results
    Investigators can be confident in their findings when using the proven, trusted, industry-leading forensic solution.
    Powerful-Search-Icon
    Powerful Search 
    Uncover critical evidence using advanced search capabilities to identify data that would be irretrievable with other computer forensic applications.
    Automation-Icon
    Automation
    Improved efficiency by automating investigative tasks with EnScript®; the scripting extension built-into EnCase® Forensic.
    Court-Vetted-Icon
    Court Vetted
    EnCase Forensic preserves data in an evidence file format (E01, L01, Lx01, Ex01) with an unsurpassed record of court acceptance.
     
    EnCase-Essentials-Portable-Training 
    EnCase Essentials: Training Included
    To help you quickly unlock the potential of EnCase® Forensic, EnCase Essentials startup training is available on-demand and at no cost. Getting started couldn't be easier.

    Learn More... 
     
    EnCase® Bit9 Analyzer customers: Effective July 1, 2011 the EnCase® Bit9 Analyzer will be sold directly by Bit9 under the product name Bit9 Analyzer. There is no change to the interoperability between Bit9 Analyzer and EnCase® branded products. Read this announcement for more information.
    EnCase® Forensic v5 End of Support Notification: Effective December 31, 2011 the v5 series of EnCase® Forensic will no longer be supported. For more information and answers to questions, please read this announcement. 
  • Features

    The powerful and effective features of EnCase® Forensic have made it the trusted standard in corporate and criminal investigation. No other product offers the same degree of functionality, acceptance, and performance.
    Features-icon-ribbon









    Passware-Logo
    Acquire from Almost Anywhere
    Acquire data from disk or RAM, documents, images, e-mail, webmail, Internet artifacts, Web history and cache, HTML page reconstruction, chat sessions, compressed files, backup files, encrypted files, RAIDs, workstations, servers, and with Version 7: smartphones and tablets.
    Forensically Sound Acquisition
    EnCase® Forensic produces an exact binary duplicate of the original drive or media, then verifies it by generating MD5 hash values for related image files and assigning CRC values to the data. These checks and balances reveal when evidence has been tampered with or altered, helping to keep all digital evidence forensically sound for use in court proceedings or internal investigations.
    Advanced Analysis
    Recover files and partitions, detect deleted files by parsing event logs, file signature analysis, and hash analysis, even within compounded files or unallocated disk space.
    Improved Productivity
    Examiners can preview results while data is being acquired. Once the image files are created, examiners can search and analyze multiple drives or media simultaneously.
    Automated de-NISTing Capabilities
    The National Software Reference Library (NSRL) is provided in the EnCase hash library format, allowing user to easily de-NIST their evidence, eliminating thousands of known files from their evidence set. This reduces the time and amount of data that needs to be analyzed significantly.
    Multiple File Viewer Support
    View hundreds of file formats in native form, built-in Registry viewer, integrated photo viewer, see results on a timeline/calendar.
    Customizable and Extensible with EnScript®
    EnCase® Forensic features EnScript® programming capabilities. EnScript®, an object-oriented programming language similar to Java or C++, allows users create to custom programs to help them automate time-consuming investigative tasks, such as searching and analyzing specific document types or other labor-intensive processes and procedures. This power can be harnessed by any level of investigator the “Case Developer” or one of the numerous built-in filters.
    Automatic Reports
    Export reports with lists of all files and folders along with detailed list of URLs, with dates and time of visits. Provide hard drive information and details related to the acquisition, drive geometry, folder structure, etc.
    Actionable Data
    Once investigators have identified relevant evidence, they can create a comprehensive report for presentation in court, to management or stakeholders in the outcome of the investigation.
    Integration to Passware Kit Forensic
    Use the Evidence Processor to automate the detection of encrypted files. Once the files are decrypted by Passware Kit Forensic* they can be easily integrated back into EnCase Forensic for further analysis.
    *Passware Kit Forensic license sold separately. Contact Sales for more information.
  • Modules

    These integrated modules extend the functionality and reach of EnCase® Forensic v7.
     
    Broad range of forensic solutions to investigate, collect, and archive data.
    Smartphone-Icon
    EnCase® Smartphone Examiner
    EnCase® Smartphone Examiner is designed for law enforcement, security analysts, and e-discovery specialists who need to review and forensically collect data from smartphone and tablet devices, such as iPhone and iPad. Investigators can process and analyze smartphone device data alongside other types of digital evidence within any Guidance Software EnCase® product.
    EVFS-icon  
    EnCase® Virtual File System (VFS) Module
    Easily mount and review evidence (such as a case, device, volume, or folder) as a read-only from outside the EnCase® Forensic environment. Useful for evidence review by investigators, opposition experts, prosecutors, defense counsel, and other non-EnCase® Forensic users. Supports multiple file systems and easily mounts RAIDS, encrypted, or compressed volumes.
    EnCase-PDE-icon  
    EnCase® Physical Disk Emulator (PDE) Module
    Mount an image of a replicated hard drive or CD in read-only mode, allowing the use of 3rd party tools for additional analysis. Also provides a platform for juries to view digital evidence in a familiar format. PDE can mount drives from several file systems, although the content may not be recognized by Windows.
    EnCase-Decryption-Suite-Icon  
    EnCase® Decryption Suite
    Tools suitable for decryption of disks, volumes, files, and folders. Capable of decrypting: Microsoft BitLocker, Microsoft BitLocker, GuardianEdge Encryption Plus/Encryption Anywhere/Hard Disk Encryption, Utimaco SafeGuard Easy, McAfee SafeBoot, WinMagic SecureDoc Full Disk Encryption, PGP Whole Disk Encryption, Microsoft Encrypting File System (EFS), CREDANT Mobile Guardian, PST (Microsoft Outlook), S/MIME encrypted email in PST files, NSF (Lotus Notes), Protected storage (ntuser.dat), Security Hive, Active Directory 2003 (ntds.dit), and others.
    FastBloc-icon  
    FastBloc® Software Edition (SE)
    A fast, reliable, and versatile solution to safely acquire of every sector of a target hard drive – even those normally outside the operating system. You can also wipe or restore drives. Plug-n-play acquisition of IDE drives, USB thumb drives, USB and Firewire external storage FastBloc® SE supports a broad range of popular IDE/SATA PCI controller cards, and select SCSI controllers.
  • Training

    Guidance Software Training
    Guidance Software Training courses and programs help organizations maximize their use of EnCase® Forensic software. We offer world-class training in enterprise investigations, e-discovery, computer security incident response, and digital forensics.
    Learn More About Training
    EnCase-Essentials-Portable-Training
    EnCase Essentials: Training Included
    To help you quickly unlock the potential of EnCase® Forensic, EnCase Essentials startup training is available on-demand and at no cost. Getting started couldn't be easier.

    Learn More...
    EnCase® Computer Forensics I
    Practical exercises and real-life simulations provides participants with an understanding of proper handling of digital evidence from seizure to acquisition, to the analysis and archiving of the data.
    Learn More | OnDemand Online Training
    EnCase® First Responder Training
    EnCase® First Responder TrainingA hands-on class on how to search and collect for digital evidence using software and hardware tools, including EnCase® Portable and Tableau hardware bridges.
    Learn More
    EnCase® Computer Forensics II
    Designed for investigators with strong computer skills, prior computer forensics training, and experience using the EnCase forensic software.
    Learn More
    EnCase v7 Transition *NEW*
    Designed for EnCase user who are upgrading from a previous version to v7, the EnCase v7 Transition course details the new features of v7, highlighting specifically the areas of the product that differ significantly from previous versions. To register for this course a user must have completed Computer Forensics II or be hold an EnCE Certification.
    Learn More
    EnCase® Advanced Computer Forensics
    In-Depth coverage of artifact analysis, data recovery, event log analysis, and advanced forensic methodology in Windows, Linux, and Macintosh OS environments. Also introduces EnScript programming for advanced task automation.
    Learn More
    EnCase® Advanced Internet Examinations
    Hands-on course explores recovery and analysis of e-mail and Internet artifacts including file sharing apps, instant messaging apps, and web browsers. Students also examine Trojan viruses, key loggers, and more.
    Learn More | OnDemand Online Training
    EnCase® Macintosh® & Linux Examinations
    EnCase® Macintosh® & Linux ExaminationsAn expert-level course that focuses on the unique characteristics of Mac OS and Linux disk layout, disk-image analysis, volume structure, and recovery techniques.
    Learn More