EnCase App Central

Extend the power of EnCase. Access, download and install software apps built by expert EnScript developers that help you get down to business – faster.

Become a Developer

Categories

Utility

$Filename Attribute Dates of tagged file(s)

This EnScript will display the (8) eight NTFS time-stamps associated with each tagged file/folder in EnCase.
By Lance Mueller
1139 Downloads
App
Utility

Active Directory Account Importer For Secure Stora...

This script allows the examiner to import user and group accounts from Active Directory into EnCase.
By Simon Key
788 Downloads
App
Utility

Android Screen Unlock

This script is designed to remove basic PIN, password or pattern lock from a connected device. This method was tested and works on Android versions from Gingerbread (2.3) to Jelly Bean (4.1). The Console tab will show commands.
By James Habben
1297 Downloads
App
Artifact

Apple System Log (ASL) File Parser

This EnScript parses user-specified Apple System Log (ASL) files in the current case. Output is by way of bookmarks and a tab-delimited spreadsheet file.
By Simon Key
1221 Downloads
App
Utility

Ares Dat File Decryptor

Decrypt files used by Ares P2P file trading program. Files: ShareH.dat ShareL.dat PHashIdx.dat.
By James Habben
959 Downloads
App
Artifact

Ares Registry Report

This script will find NTUSER.dat files and extract the subkey [\\Software\\Ares] into a bookmark. It will also interpret a number of known values and decrypt some values that are encrypted.
By James Habben
1009 Downloads
App
Utility

Assisted PST/OST Mounting in EnCase

The script assists in mounting Microsoft Outlook PST and OST files for use in EnCase.
By Jacques Malan
671 Downloads
App
Artifact

AutoCAD DWG Summary Info Reader

This EnScript allows the examiner to read document summary information from AutoCAD DWG files. The script supports file-versions from 2004 to 2013.
By Simon Key
299 Downloads
App
Artifact

Binary Plist Finder

This script searches specified items for binary property-list (plist) files. It was designed primarily to recover plist files from unallocated clusters but can also be used to recover plists embedded in other files (records or entries).
By Simon Key
285 Downloads
App
Artifact

BitTorrent Bencode File Finder

This EnScript can be used to find and decode bencoded files of the type used by several BitTorrent clients.
By Simon Key
337 Downloads
App
Artifact

BitTorrent Bencode Viewer Plugin

This is an EnCase plugin that allows the examiner to view the bencoded files of the type used by many BitTorrent clients.
By Simon Key
279 Downloads
App
Utility

Bookmark Filter Plugin

This self-installing plugin allows the user to select bookmarks matching a given condition. It is particularly useful when trying to identify bookmarks containing specific text in the comment.
By Simon Key
328 Downloads
App
Utility

Categorize & Bookmark by File Extensions

EnCase v7 EnScript to define criteria in a condition dialog and then bookmark those files into bookmark subfolders based on extensions
By Lance Mueller
589 Downloads
App
Utility

Categorize Internet History

Review your case internet history in categories. Quickly identify URLs related to adult material, webmail, games, etc. Currently uses data from www.urlblacklist.com as source for categorized data.
By James Habben
1554 Downloads
App
Utility

CD Image Loader Plugin

This EnScript loads one or more CD/DVD-ROM ISO images into the current case. Supports multi-part images of the type created by FTK Imager.
By Simon Key
349 Downloads
App
Utility

CompoundFileMounter (EnFilter)

This is a File Mounter. Like the V6 file mounter, but for V7 and to mount the files not included in the Evidence processor.
By James Gagen
1121 Downloads
App
Utility

Comprehensive Case Template

This template may serve you as basis for your own specific template and includes many Bookmark folders for often encountered topics during your exams.
By Manfred Hatzesberger
421 Downloads
App
Utility

Conditions Launcher

This EnScript will simultaneously run all the conditions from within a specific folder.
By Bartosz Kaczmarek
313 Downloads
App
Utility

Contextual Data Builder

Importing customer contextual data enables you to integrate your enterprise or third-party database of whitelisted, blacklisted, and watchlisted hashes as you extract, transform, and load data to the analytics data warehouse.
By John Lukach
397 Downloads
App
Utility

Copy Web Browser Files

A simple script used to identify all browser history cookie and cache files in a case and copy them out for further processing using 3rd party tools.
By Paul Eric Tew
2013 Downloads
App
Utility

Create LEF From Folders Using Logical and UNC Path

Creates an EnCase logical evidence file from the contents of one or more folders specified by the user.
By Simon Key
265 Downloads
App
Utility

Create Result Set Excluding Unwanted Items

Allows the examiner to create a result-set that excludes unwanted items by way of them having a 'known' hash value or other undesirable properties (name, size, file extension, etc).
By Simon Key
629 Downloads
App
Utility

Create Result-Sets For Hash-Categories

This script creates result-sets for each of the hash-categories associated with active hash-sets contained in the current case's active hash library/libraries.
By Simon Key
580 Downloads
App
Utility

Create Result-Sets For Specific Document-Types

This EnScript allows the examiner to create result-sets containing items matching user-specified file-types.
By Simon Key
625 Downloads
App
Utility

C-TAK (Cyber-Threat Analytics Knowledgebase) Trial...

C-TAK provides examiners with accurate identification of cyber threats that may directly impact investigations. The C-TAK trial includes Keylogger, Rootkit and Trojan datasets built in.
By WetStone Technologies Inc.
99 Downloads
App
Utility

DFLabs DIM Integration-NG

Created by DFLabs this EnScript enables you to add EnCase evidence and bookmark data to IncMan-NG suite.
By DFLabs SRL
197 Downloads
App
Utility

DFLabs IncMan Integration-NG

This EnScript allows the user to upload remote node snapshot information from Sweep Enterprise into IncMan-NG the Incident Response Management from DFLabs.
By DFLabs SRL
211 Downloads
App
Reporting

Drive Space Audit

This EnScript will audit the space of all devices in the case. A table will be built in the bookmarks tab as a summary to show usage of devices in the case.
By James Habben
1044 Downloads
App
Artifact

DS_Store Parser

This script parsers user-specified .DS_Store files created by Mac OS X. One of the most common reasons for wanting to examine these files is to determine the original name and path of files/folders in the Trash folder.
By Simon Key
1562 Downloads
App
Utility

Dumpkeychain

Dumpkeychain is a Windows utility for decrypting credentials from Mac OS X system and user keychains given the associated system-key-file or keychain-password respectively.
By Simon Key
1628 Downloads
App
Reporting

E-mail Address Finder

This EnScript will locate, bookmark, and count all unique e-mail addresses in a case.
By Ryan Jay Ollerenshaw
1437 Downloads
App
Utility

EMLX to EML Mail Converter

Convert Apple Mail EMLX files to EML/MBOX format, which can be then read by other e-mail clients and processed by EnCase.
By Simon Key
1304 Downloads
App
Incident Response

EnCase Integrated Threat Toolkit (EITT)

EnCase Integrated Threat Toolkit (EITT) is a GUI interface and aggregate for a number of EnCase® Enterprise functions and over 15 open source tools designed to assist in DFIR investigations.
By Guidance Software
1185 Downloads
App
Utility

Encryption Finder

Scans evidence files and devices for known encryption markers.
By Graham Jenkins
442 Downloads
App
Utility

EnDiff

This script allows an EnScript developer to quickly identify newly introduced classes, methods, and properties in EnCase.
By Simon Key
567 Downloads
App
Utility

EnParse - 30-Day Free Trial

30-day free trial of EnParse. Find what is in multiple evidence files at once without full export, prepare useful reports for clients.
By Manishaben Chovatiya
12 Downloads
App
General

EnScript Finder

This helpful EnScript lets you search all your downloaded EnScripts and either launch them or open the folder where they were found.
By Guidance Software
462 Downloads
App
Incident Response

EnScript to send file metadata directly to Splunk

EnCase EnScript to send data directly to SPLUNK for IR, Investigations and Timelines.
By Lance Mueller
706 Downloads
App
Utility

Evidence File Converter

EnScript converts blue-checked EnCase evidence files in the evidence tab to bitstream, dd-type disk images with the option to use the Apple multi-part DMG naming convention.
By Simon Key
912 Downloads
App
Artifact

EVTX Log Entry Finder

This EnScript finds and bookmarks deleted records from Microsoft Windows EVTX event-log files.
By Simon Key
692 Downloads
App
Artifact

Exif GPS Information Reader

Search for bookmark and decode Exif metadata with the option to view GPS Exif coordinates in Google Earth automatically.
By Simon Key
2044 Downloads
App
Artifact

Exif Viewer Plugin

The is a self-installing application plugin that enables the user to right-click on an Exif JPEG file in order to view and bookmark the Exif metadata that it contains.
By Simon Key
2375 Downloads
App
Utility

Export and Bookmark Files Based On Extension

Use this EnScript to extract files into separate folders based on extension. The script will create a tab-delimited index file containing the file-system metadata specified by the examiner. Detects and avoids long output paths automatically.
By Simon Key
398 Downloads
App
Utility

Export by Extension

Export files based on extension
By Lance Mueller
789 Downloads
App
Utility

Extract Bookmarked Items With Bookmark Folder Path

This EnScript extracts selected bookmarked items to a nominated folder whilst preserving the bookmark-folder path. The examiner can opt to extract e-mail records as MSG
By Simon Key
362 Downloads
App
Artifact

Facebook MSG Finder

This Enscript will find FaceBook artifacts in tagged files and create a detailed bookmark.
By Ryan Jay Ollerenshaw
742 Downloads
App
Utility

File Block Hash Map Analysis

This EnScript uses block-based hash analysis in order to locate and recover one or more target files in circumstances where other methods are likely to fail.
By Simon Key
803 Downloads
App
Utility

File Directory Listing

This EnScript creates a directory listing of all items in the case and makes a .CSV file.
By Joshua Clevenger
812 Downloads
App
Utility

File Exporter

This program exports files from the current Entry or Results view based upon user selected criteria.
By Karl Winrow
297 Downloads
App
Utility

File Properties

File Properties is a script to easily cut/paste properties on selected files to your investigation report without using bookmarks.
By Guidance Software
513 Downloads
App
Utility

File Remediator

FileRemediator uses EnCase's built-in wiping function to target and wipe individual files and folders on a local device and then create all the necessary logs.
By Thomas Plunkett
224 Downloads
App
Utility

FileHash2SQLite

Map File Hashes to Case Numbers and Examiners using an SQLite database
By Greg Farnham
320 Downloads
App
Artifact

Find and Parse Prefetch Files in Unallocated

This EnScript searches unallocated clusters for deleted prefetch data. If found, the EnScript will parse out the name of the executable, last run time and run count.
By Lance Mueller
1283 Downloads
App
Utility

Find E-Mail Attachments By Extension

Finds e-mail attachments with file-extensions specified by the examiner. Searches archive attachments (including nested archives) by default.
By Simon Key
1367 Downloads
App
Utility

Find Entries by Hash Category Plus (EnFilter)

This is a modified version of the v7.08 Filter in EnCase to Find Entries by Hash Category
By Simon Key
852 Downloads
App
Utility

Find Registries with Key ValuesV1

This EnScript examines the file system for files with the extension “dat”,” reg”, “hve” or none wth a file header of “reg.” If the file name is settings.dat, then it is examined for key values.
By Simon Key
882 Downloads
App
Utility

Find Unique Records by Hash (EnFilter)

This is a modified version of the Filter in EnCase to Find Unique Entries by Hash, I have modified the filter to work on records and will match on the MD5 hash.
By James Gagen
865 Downloads
App
General

Generate ED2K Hash Values

This EnScript will generate ED2K hash values for the purpose of comparing them to some known bad files based on those ED2K hash values.
By Lance Mueller
360 Downloads
App
Utility

Generic XML Viewer Plugin

Use an extended context-menu option to view and bookmark data contained within XML files.
By Simon Key
373 Downloads
App
Artifact

GigaTribe Download State Information Finder

The GigaTribe Download State Information Finder searches for information stored whilst a download is progressing on a GigaTribe user’s computer.
By Simon Key
748 Downloads
App
Artifact

GigaTribe V3 Chat Parser

Locates and parses chat records originating from GigaTribe V3 chat-log files.
By Simon Key
757 Downloads
App
Incident Response

Hacker Offender

This App is designed to discover files that are hidden by rootkits. It will place all detected files into a LEF for further analysis. This may include the malware and additional files deemed important by the attacker.
By James Habben
1167 Downloads
App
Utility

Has Attachment by Category (EnFilter)

This filter works on Records in email and will return Records with Attachments that match the selected category. The Source of the filter can be viewed to see the changes made.
By James Gagen
660 Downloads
App
Utility

Hash Calculator Plugin

This EnScript is a plugin that allows the examiner to calculate CRC-32, Adler MD-5, SHA-1, SHA-256 and SHA-512 hash values for the item highlighted in the EnCase GUI.
By Simon Key
471 Downloads
App
Utility

Hash List Builder

Generate a matching file set for blue checked items that have had their MD5 hashes processed for import into EnCase Endpoint Security.
By John Lukach
969 Downloads
App
Utility

Hash List Importer

This EnScript is designed to create a new EnCase hash-library either from a list of hashes in tab-delimited format or from the NSRLFile.txt file.
By Simon Key
1250 Downloads
App
Artifact

HFS Journal Parser

HFS Journal Parser finds and parses Catalog file record in HFS+/HFSX .journal file.
By Teru Yamazaki
1039 Downloads
App
Artifact

iChat Message Parser

This EnScript parses *.ichat messages of the type created by the Mac OS X Messages application.
By Simon Key
489 Downloads
App
Artifact

Identify and Extract Date & Time Changes

EnScript to identify 4616 events (date and time change) that exceed a user specified number of minutes allowing the user to quickly discard Time Server syncs.
By Lynette Goh
376 Downloads
App
Utility

Image Analyzer - 30 Day Free Trial

Free 30 day trial with unlimited image scans – download today and accelerate your investigation. Image Analyzer scans image files within entries and records to identify pornographic content.
By Image Analyzer
145 Downloads
App
Utility

Import Network Nodes Into EE Plugin

Import network hosts and IP ranges from a spreadsheet into the EnCase Enterprise network layout.
By Simon Key
689 Downloads
App
Reporting

Inventory

Hash and parse all your case files to create an inventory of your cases.
By James Habben
559 Downloads
App
Utility

JPEG File Exporter

This app will export tagged jpeg image files and add the jpeg extension to the exported file.
By Ryan Jay Ollerenshaw
976 Downloads
App
Artifact

JPEGSnoop

View EXIF metadata found in JPEG images within EnCase-- no need for a third-party application to view GPS coordinates, camera make and model, etc.
By Casimer Szyper
1865 Downloads
App
Utility

JSON Viewer Plugin

This EnScript plugin allows the user to view and bookmark application data stored in JavaScript Object Notation JSON files.
By Simon Key
531 Downloads
App
Reporting

Keyword Search and Proximity Extract

Keyword search and proximity extract is designed to do Fuzzy string extraction by grouping relevant string fragments together.
By Jacques Malan
438 Downloads
App
Utility

Keyword Search with Range Bookmarking

This EnScript allows the user to perform a raw keyword search of entries and records and bookmark a user-specified range of bytes before and after each search-hit.
By Simon Key
769 Downloads
App
Utility

Known _met Search and Parse

This EnScript will search all tagged items for known.met record fragments from eMule 0.5.
By William Lynn
818 Downloads
App
Utility

Last Folder Plugin

This EnScript allows the user to open Windows Explorer and show the current case's export folder.
By Simon Key
731 Downloads
App
Artifact

Link File & Jump List Parser

This EnScript parses recent file-system activity from Microsoft Windows shortcut-link and jump-list files.
By Simon Key
1138 Downloads
App
Artifact

Logon Banner and Text (from SYSTEM registry hive f...

This is an EnScript that extracts and bookmarks the local logon banner and logon text. Verifies corporate policies, such as "further used denotes no expectation of privacy".
By Thomas Hilk
214 Downloads
App
Utility

Low Hanging Fruit

Low Hanging Fruit Please extracts file name path and MD5 to a SQLite database that also contains an Item Moniker data for each entry.
By John Lukach
1326 Downloads
App
Artifact

Mac OS X AutoLogin Password Decoder

This is a small utility that will decrypt the user-password for a user set to to automatically log-in to a Mac OS X system.
By Simon Key
1188 Downloads
App
Artifact

Mac OS X BinaryCookie File Parser

This script parsers user-specified Mac OS X binary cookie files. Output is by way of bookmarks and a tab-delimited spreadsheet file.
By Simon Key
954 Downloads
App
Artifact

Mac OS X Log Entry Finder

This script searches user-specified Mac OS X plaintext log-files for log-entries containing one or more keywords.
By Simon Key
1091 Downloads
App
Artifact

Mac OS X OpenBSM Audit Log Parser

This EnScript parses Mac OS X OpenBSM audit-logs, which typically contain details of events relating to audit-control, user-logon and group/user creation/modification/deletion.
By Simon Key
278 Downloads
App
Artifact

Mac OS X Outlook Mail Converter

This EnScript is designed to convert Microsoft Outlook *.olk14MsgSource and *.olk14MsgSource message-files to EML files and a logical evidence file that can be processed by EnCase.
By Simon Key
167 Downloads
App
Artifact

Mac OS X Previous Versions Chunk Storage Parser

Certain Mac OS X applications support the storage of previous versions of files. This EnScript will recover those files and write them to a logical evidence file so that they can be examined.
By Simon Key
379 Downloads
App
Artifact

Mac OS X QuickLook Thumbcache Parser

Extracts thumbnail images from Mac OS X QuickLook thumbnail cache files.
By Simon Key
1079 Downloads
App
Artifact

Mac OS X Time Machine Parser

This EnScript allows the examiner to resolve the backup paths of blue-checked files in a Mac OS X Time Machine volume without having to make a copy of the volume available to a Macintosh computer.
By Simon Key
554 Downloads
App
Utility

MACE Timeline

A Script that will order changes in files or metadata chronologically. This will provide a clean view of actions from the computer in the order they happened.
By James Habben
1574 Downloads
App
Reporting

Manfreds Berichtsvorlage (NSRL 2.49)

Dieses umfassende Berichtstemplate kann als Basis für Ihre eigene Vorlage dienen. Sie ist sehr umfangreich und enthält Bookmark-Verzeichnisse für die häufigsten Topics Ihrer Untersuchungen.
By Manfred Hatzesberger
164 Downloads
App
Reporting

Manfred's Comprehensive Case Template

This template may serve you as basis for your own specific template and includes many Bookmark folders for often encountered topics during your exams.
By Manfred Hatzesberger
495 Downloads
App
Reporting

Manfred's Comprehensive Case Template (NSRL 2.49)

This template may serve you as basis for your own specific template and includes many Bookmark folders for often encountered topics during your exams.
By Manfred Hatzesberger
242 Downloads
App
Artifact

Matching File Creator

This EnScript allows the examiner to tag items of interest and export a tab-delimited CSV file with the name, MD5 hash value, and logical size of the selected tags.
By Joseph Gaval
202 Downloads
App
Incident Response

MD5 Malware Database Check

Right click on a selected file to compare it against the VirusToal and/or ThreatExpert databases and determine if it is known malware.
By Guidance Software
454 Downloads
App
Incident Response

MemoryAnalysis

Process Windows, Linux, and OS X memory images and find running processes, parents, create dates, and more.
By Casimer Szyper
2926 Downloads
App
Artifact

Messenger Protocol Fragments

A script to search for protocol fragments of MSN Messenger (or MSN Live Messenger) chat.
By Paul Eric Tew
1135 Downloads
App
General

MFT Date Comparator

This script is designed to identify potentially suspect files by analyzing timestamp differences in the NTFS MFT standard information and filename attributes of each file.
By Simon Key
759 Downloads
App
Incident Response

NETSH Packet Capture

NETSH Packet Capture allows network traffic sniffing on Microsoft Windows 7 and newer machines using natively installed NETSH with a Servlet with Remediation from EnCase Endpoint Security.
By John Lukach
406 Downloads
App
Reporting

NirSoft ESEDatabaseView Plugin

NirSoft ESEDatabaseView v1.15 executable integration with EnCase for centralized reporting of Extensible Storage Engine (ESE) a.k.a. JET Blue EDB files through the use of bookmarks.
By John Lukach
709 Downloads
App
Artifact

Nokia Lumia 610 SMS

This script will parse out SMS from a Nokia Lumia 610 mobile phone binary dump.
By Karl Winrow
468 Downloads
App
Artifact

NTFS $UsnJrnl Parser

This EnScript allows the user to parse valuable information logging NT file-system operations including time files that have been created, deleted and renamed.
By Simon Key
527 Downloads
App
Utility

Office 97-2003 Metadata Processor

This EnScript parses metadata from Microsoft Office documents of the format used prior to Office 2007.
By Simon Key
471 Downloads
App
Utility

OfficeRecovery 2013 Ultimate - Trial Version

Repair and examine the contents of corrupted files in collected evidence. Word Excel digital images and dozens of other formats are supported.
By Recoveronix Software
546 Downloads
App
General

Old School Search Hit Viewer

The Old School Search Hit Viewer will display search hits in a table; the hits are highlighted with a user-specified amount of context visible around the search hit.
By Kimberly Stone
465 Downloads
App
Artifact

Outlook PST & OST Deleted File Recovery

This script is designed to recover deleted PST/OST files.
By Simon Key
288 Downloads
App
Artifact

Parse PE Executable for String Resources

This EnScript specifically targets a resource known as "VS_VERSION_INFO" which contains metadata about the specific executable, including the manufacturer name, original filename, version info and other useful information.
By Lance Mueller
628 Downloads
App
Artifact

Parse Recent RDP sessions from NTUSER.DAT Files

This EnScript was designed as a "quick hit" to parse and show the MRU values for the Terminal server client for each user.
By Lance Mueller
1015 Downloads
App
Artifact

Parse the setupapi.dev.log of USBs

This EnScript will parse the setupapi.dev.log (Windows Vista/7) for USB connected events and display this in the console tab
By Simon Key
1793 Downloads
App
Artifact

Parse Wireless Access Points in Vista, Win7, & Win...

EnScript to extract & display information about wireless networks that have been connected to. Supports analysis of Windows Vista, 7 & 8.
By Lance Mueller
1202 Downloads
App
Artifact

PE Examiner

Parse single or multiple .EXE files and extract all information encoded into the PE (COFF) header. Also works on memory dumps or unallocated space.
By Casimer Szyper
1129 Downloads
App
Artifact

Plist Parser

This EnScript allows the examiner to bookmark and parse multiple Apple property-list (plist) files.
By Simon Key
603 Downloads
App
Artifact

Plist Viewer Plugin

Use an extended context-menu option to bookmark, decode and extract data contained in Apple property list (.plist) files; automatically view plist files embedded in other plist files.
By Simon Key
403 Downloads
App
Utility

Pre-Evidence Processing Tasks

Quickly gather needed information before Evidence Processing.
By Tim Taylor
1342 Downloads
App
Artifact

Prefetch Dump

This EnScript parses application usage information stored in Microsoft Windows prefetch files. This version supports Window XP through Windows 10 and includes a run-count and one or more last-run dates.
By Simon Key
972 Downloads
App
Artifact

Prefetch Parser

This EnScript parses prefetch files with the standard file header “0x53, 0X43, 0X43, 0x41” (or “SCCA”) at offset 04 for Windows XP, Vista, 7 and 8.
By Simon Key
1508 Downloads
App
Artifact

Print Spool - SHD & SPL Parser

This EnScript extracts and bookmarks the admin data from the printer shadow files and bookmarks EML print data from the printer spool files.
By Lynette Goh
583 Downloads
App
Utility

Quick Bookmark Folders

Quickly make bookmark folders for each device in your case. Automate making bookmark folders and subfolders for each device in your case. Along with bookmarking each device and each volume in the case. User configurable subfolders.
By Brett Liddicoet
350 Downloads
App
Artifact

RDP Cached Bitmap Extractor

This EnScript parses bitmap data cached by the Microsoft Windows Terminal Services (Remote Desktop Protocol - RDP) client.
By Simon Key
522 Downloads
App
Utility

Record to Excel

Use Record2Excel to export records to Microsoft Excel. This script works with any records list which can be tagged. It will export all record properties (fields values) to Excel. Requires Microsoft Excel.
By Guidance Software
518 Downloads
App
Artifact

Registry Files Exporter

Export Windows Registry files from Windows OS
By Isaac Lee
1377 Downloads
App
Utility

RegRipper Launcher

This EnScript runs RegRipper directly from EnCase. Automatically bookmark results or load them in a Micorsoft Word / Open Office document. Requires RegRipper.
By Guidance Software
563 Downloads
App
Utility

Remote Agent Deployment

This EnScript allows the user to remotely deploy agents across their enterprise.
By Guidance Software
443 Downloads
App
Utility

Retention Analyzer

Calculates the volume based on logical size in bytes per month based on MAC times for an eight year time frame that are not tagged as 'Known'.
By John Lukach
648 Downloads
App
Artifact

Safari Cache Evidence Processor Module

This is a self-installing EnCase Evidence Processor module that parses Mac OS X Safari cache content.
By Simon Key
279 Downloads
App
Utility

Safari Form Values Decryptor

Use this tool to extract the autofill form values from the encrypted plist that Safari uses. It requires the user’s keychain to decrypt the AES-128 data.
By Simon Key
1053 Downloads
App
Utility

Search and Bookmark Specific Data Types

This EnScript allows the examiner to search for one or more keywords and bookmark the resultant search-hits using specific data-types (picture, ROT13, low ASCII, hex, etc).
By Simon Key
829 Downloads
App
Utility

Search Hits Preview

This EnScript creates a search hit preview file that can be imported into Excel.
By Ryan Jay Ollerenshaw
425 Downloads
App
Artifact

SEEB USB - Mounted Devices Report

Script will create detailed Excel, CSV, console & bookmark reports on Mounted, USB, portable devices found in the registry and setupapi logs.
By Brian Jones
3018 Downloads
App
Artifact

ShimCache Parser

This EnScript mounts all SYSTEM registries found in the current evidence, parses the Application Compatility Cache registry key and output the result onto the console, bookmarks and tab-delimited CSV file.
By Isaac Lee
789 Downloads
App
Utility

Show or Hide Items with a Selected Tag

This Filter will enable the user to show or hide items based on the tag status.
By James Gagen
430 Downloads
App
Utility

SimpleSearch

This EnScript searches for keywords in every open case and bookmarks the files.
By Iosif Dan Laszlo
794 Downloads
App
Artifact

Skype Chatsync IP Addresses

This EnScript will parse out the IP addresses from Skype chatsync files and write them to the console as well as bookmark the artifacts.
By Lance Mueller
956 Downloads
App
Utility

SQLiteQuery

Allows SQL querying of all SQLite databases from within EnCase.
By Doug Collins
1544 Downloads
App
Utility

Startup Manager

Startup Manager lets you select EnScripts and EnPacks to start automatically when EnCase starts.
By Carmona Pereyra
759 Downloads
App
Utility

System Snap Shot

System Snap Shot collects information regarding software used, system settings, user names, last login information, and connections made that would allow data to be moved off the machine.
By Jordan venderBuhs
263 Downloads
App
Artifact

SysTools Outlook Exporter v2.2 (Demo Version)

SysTools Outlook Exporter is an EnCase plugin which allows you to export email evidence found with EnCase forensic to an Outlook (.pst) file WITHOUT Outlook.
By SysTools Software
390 Downloads
App
Incident Response

Team Cymru Malware Hash Registry Search

Review evidence files to assist in learning if any might correspond to malware.
By Jeffrey Savoy
948 Downloads
App
Incident Response

ThreatAnalyzer Automation Toolkit

ThreatAnalyzer provides best in class dynamic file analysis which enables the investigator to quickly determine any behaviors a given file sample may exhibit.
By Cisco Systems
325 Downloads
App
Utility

ThreatGRID Malware Analysis and Intelligence for E...

Threat Grid Malware Analysis and Intelligence for EnCase® provides direct integration with Threat Grid, the first unified malware analysis and threat intelligence solution. Threat Grid provides in-depth analysis and correlates attack-related artifacts.
By Cisco Systems
772 Downloads
App
Artifact

Thumbcache Parser

This script parses the thumbcache_*.db files used to store thumbnail images generated as a result of viewing pictures in Windows Explorer under Windows Vista, 7, 8/8.1 and 10.
By Simon Key
549 Downloads
App
Artifact

Timezone Info Prior to Processing

This EnScript allows the Examiner to determine the timezone settings of each device prior to running the EnCase Evidence Processor.
By Jamey Tubbs
1646 Downloads
App
Reporting

Umfassende Berichtsvorlage

Dieses umfassende Berichtstemplate kann als Basis für Ihre eigene Vorlage dienen. Sie ist sehr umfangreich und enthält Bookmark-Verzeichnisse für die häufigsten Topics Ihrer Untersuchungen.
By Manfred Hatzesberger
203 Downloads
App
Utility

UNC Path Preview and Acquire

Use this script to preview the files and folders on a remote device through SMB share. No need to map to the share first since this allows for using credentials.
By James Habben
448 Downloads
App
Utility

Unmount Compound File

This will add a right click option to unmount a compound file. This can be used to try a different password or just get rid of the additional items.
By James Habben
861 Downloads
App
Utility

UsnJrnl Record Keyword Search and Export to CSV

This script will prompt for a keyword from the user then search selected tagged items for that keyword.
By William Lynn
1028 Downloads
App
Utility

Video Split

This EnScript uses Ffmpeg to create thumbnail images from selected movies. The images are automatically made into a LEF file which can then be added to a case.
By Guidance Software
474 Downloads
App
Incident Response

VirusShare.com Contextual Data

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts samples of malicious code.
By John Lukach
571 Downloads
App
Incident Response

VirusShare.com Hash Library

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts samples of malicious code.
By John Lukach
917 Downloads
App
Incident Response

VirusShare.com Hash Sets

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts samples of malicious code.
By John Lukach
811 Downloads
App
Incident Response

VirusTotal Bookmark

This EnScript provides a quick automated way to tag files and then automatically submit their hash values to Virus Total for analyzing.
By Lance Mueller
513 Downloads
App
Incident Response

Volatility Reporting Plugin

Volatility 2.4 Standalone executable integration with EnCase for centralized reporting of memory forensic results through the use of bookmarks.
By John Lukach
1802 Downloads
App
Artifact

VSS Examiner

Quickly and easily identify and preserve data of interest in Microsoft Windows volume shadow copies.
By Simon Key
3179 Downloads
App
Artifact

Webpage Rebuilder

This script will export and rebuild tagged records into a local file to view with a browser.
By James Habben
1808 Downloads
App
General

What's New In App Central

This EnScript will find any new or updated EnScripts at EnCase App Central.
By Guidance Software
617 Downloads
App
Artifact

Windows 8 and 8.1 Mail Finder

Finds deleted e-mail messages originating from the Windows 8 and 8.1 Mail applications.
By Simon Key
564 Downloads
App
Utility

Windows Drive Letter Assignments

This EnScript is designed to identify Windows drive-letter assignments for volumes in the current case that have been identified as originating from fixed disks.
By Simon Key
808 Downloads
App
Artifact

Windows Event Log Export

This EnScript searches for pre-vista event log files (*.evt) and checks if they are flagged dirty.
By James Habben
1612 Downloads
App
Utility

Windows Executable Packer Detection

Analyze Windows executables and detect modification by a packer or cryptor.
By James Habben
1669 Downloads
App
Artifact

Windows Live Mail to MBOX Converter

This script converts a Windows Live Mail e-mail store to a sequence of MBOX files in a logical evidence file that can be added to a case and processed in the usual way.
By Simon Key
819 Downloads
App
Utility

Windows Quick View Plugin

This is an EnScript plugin that allows the examiner to quickly open evidence-items using the default Windows viewer.
By Simon Key
735 Downloads
App