EnCase App Central

Extend the power of EnCase. Access, download and install software apps built by expert EnScript developers that help you get down to business – faster.

Become a Developer

Categories

Utility

$Filename Attribute Dates of tagged file(s)

This EnScript will display the (8) eight NTFS time-stamps associated with each tagged file/folder in EnCase.
By Lance Mueller
6468 Downloads
App
Utility

Active Directory Account Importer For Secure Stora...

This script allows the examiner to import user and group accounts from Active Directory into EnCase.
By Simon Key
7625 Downloads
App
Utility

Android Screen Unlock

This script is designed to remove basic PIN, password or pattern lock from a connected device. This method was tested and works on Android versions from Gingerbread (2.3) to Jelly Bean (4.1). The Console tab will show commands.
By James Habben
6860 Downloads
App
Artifact

Apple System Log (ASL) File Parser

This EnScript parses user-specified Apple System Log (ASL) files in the current case. Output is by way of bookmarks and a tab-delimited spreadsheet file.
By Simon Key
9514 Downloads
App
Utility

Ares Dat File Decryptor

Decrypt files used by Ares P2P file trading program. Files: ShareH.dat ShareL.dat PHashIdx.dat.
By James Habben
5611 Downloads
App
Artifact

Ares Registry Report

This script will find NTUSER.dat files and extract the subkey [\\Software\\Ares] into a bookmark. It will also interpret a number of known values and decrypt some values that are encrypted.
By James Habben
4953 Downloads
App
Utility

Assisted PST/OST Mounting in EnCase

The script assists in mounting Microsoft Outlook PST and OST files for use in EnCase.
By Jacques Malan
5875 Downloads
App
Artifact

AutoCAD DWG Summary Info Reader

This EnScript allows the examiner to read document summary information from AutoCAD DWG files. The script supports file-versions from 2004 to 2013.
By Simon Key
4351 Downloads
App
Artifact

Binary Plist Finder

This script searches specified items for binary property-list (plist) files. It was designed primarily to recover plist files from unallocated clusters but can also be used to recover plists embedded in other files (records or entries).
By Simon Key
8751 Downloads
App
Artifact

BitTorrent Bencode File Finder

This EnScript can be used to find and decode bencoded files of the type used by several BitTorrent clients.
By Simon Key
5068 Downloads
App
Artifact

BitTorrent Bencode Viewer Plugin

This is an EnCase plugin that allows the examiner to view the bencoded files of the type used by many BitTorrent clients.
By Simon Key
4361 Downloads
App
Utility

Bookmark Filter Plugin

This self-installing plugin allows the user to select bookmarks matching a given condition. It is particularly useful when trying to identify bookmarks containing specific text in the comment.
By Simon Key
4020 Downloads
App
Utility

Case Analyzer and Sweep Enterprise Data Extraction

Use this script to batch-extract selected Case Analyzer and Sweep Enterprise reports to comma-delimited spreadsheets.
By Simon Key
777 Downloads
App
Utility

Categorize & Bookmark by File Extensions

EnCase v7 EnScript to define criteria in a condition dialog and then bookmark those files into bookmark subfolders based on extensions
By Lance Mueller
4521 Downloads
App
Utility

Categorize Internet History

Review your case internet history in categories. Quickly identify URLs related to adult material, webmail, games, etc. Currently uses data from www.urlblacklist.com as source for categorized data.
By James Habben
7984 Downloads
App
Utility

CD Image Loader Plugin

This EnScript loads one or more CD/DVD-ROM ISO images into the current case. Supports multi-part images of the type created by FTK Imager.
By Simon Key
4373 Downloads
App
Utility

CompoundFileMounter (EnFilter)

This is a File Mounter. Like the V6 file mounter, but for V7 and to mount the files not included in the Evidence processor.
By James Gagen
6032 Downloads
App
Utility

Comprehensive Case Template

This template may serve you as basis for your own specific template and includes many Bookmark folders for often encountered topics during your exams.
By Manfred Hatzesberger
4597 Downloads
App
Utility

Conditions Launcher

This EnScript will simultaneously run all the conditions from within a specific folder.
By Bartosz Kaczmarek
4211 Downloads
App
Utility

Contextual Data Builder

Importing customer contextual data enables you to integrate your enterprise or third-party database of whitelisted, blacklisted, and watchlisted hashes as you extract, transform, and load data to the analytics data warehouse.
By John Lukach
3966 Downloads
App
Utility

Copy Web Browser Files

A simple script used to identify all browser history cookie and cache files in a case and copy them out for further processing using 3rd party tools.
By Paul Eric Tew
7341 Downloads
App
Artifact

Cortana Search Decoder

Decodes the search terms stored in IndexedDB.edb files used by the Microsoft Windows Cortana search function.
By Simon Key
3164 Downloads
App
Utility

Create LEF From Folders Using Logical and UNC Path

Creates an EnCase logical evidence file from the contents of one or more folders specified by the user.
By Simon Key
9473 Downloads
App
Utility

Create Result Set Excluding Unwanted Items

Allows the examiner to create a result-set that excludes unwanted items by way of them having a 'known' hash value or other undesirable properties (name, size, file extension, etc).
By Simon Key
4595 Downloads
App
Utility

Create Result-Sets For Hash-Categories

This script creates result-sets for each of the hash-categories associated with active hash-sets contained in the current case's active hash library/libraries.
By Simon Key
4487 Downloads
App
Utility

Create Result-Sets For Specific Document-Types

This EnScript allows the examiner to create result-sets containing items matching user-specified file-types.
By Simon Key
7016 Downloads
App
Utility

Credit Card Number Search With Luhn Verification

This script finds credit card numbers which are valid according to the Luhn test.
By Simon Key
1239 Downloads
App
Utility

C-TAK (Cyber-Threat Analytics Knowledgebase) Trial...

C-TAK provides examiners with accurate identification of cyber threats that may directly impact investigations. The C-TAK trial includes Keylogger, Rootkit and Trojan datasets built in.
By WetStone Technologies Inc.
99 Downloads
App
Utility

Deleted SQLite Database File Recovery

This script is designed to recover deleted database files last modified by SQLite version 3.7 or later.
By Simon Key
966 Downloads
App
Utility

DFLabs DIM Integration-NG

Created by DFLabs this EnScript enables you to add EnCase evidence and bookmark data to IncMan-NG suite.
By DFLabs SRL
3683 Downloads
App
Utility

DFLabs IncMan Integration-NG

This EnScript allows the user to upload remote node snapshot information from Sweep Enterprise into IncMan-NG the Incident Response Management from DFLabs.
By DFLabs SRL
3995 Downloads
App
Reporting

Drive Space Audit

This EnScript will audit the space of all devices in the case. A table will be built in the bookmarks tab as a summary to show usage of devices in the case.
By James Habben
7297 Downloads
App
Artifact

DS_Store Parser

This script parsers user-specified .DS_Store files created by Mac OS X. One of the most common reasons for wanting to examine these files is to determine the original name and path of files/folders in the Trash folder.
By Simon Key
9847 Downloads
App
Utility

Dumpkeychain

Dumpkeychain is a Windows utility for decrypting credentials from Mac OS X system and user keychains given the associated system-key-file or keychain-password respectively.
By Simon Key
7601 Downloads
App
Reporting

E-mail Address Finder

This EnScript will locate, bookmark, and count all unique e-mail addresses in a case.
By Ryan Jay Ollerenshaw
6725 Downloads
App
Utility

EMLX to EML Mail Converter

Convert Apple Mail EMLX files to EML/MBOX format, which can be then read by other e-mail clients and processed by EnCase.
By Simon Key
6555 Downloads
App
Utility

Encryption Finder

Scans evidence files and devices for known encryption markers.
By Graham Jenkins
6134 Downloads
App
Utility

EnDiff

This script allows an EnScript developer to quickly identify newly introduced classes, methods, and properties in EnCase.
By Simon Key
4491 Downloads
App
Utility

EnParse - 30-Day Free Trial

30-day free trial of EnParse. Find what is in multiple evidence files at once without full export, prepare useful reports for clients.
By Manishaben Chovatiya
12 Downloads
App
General

EnScript Finder

This helpful EnScript lets you search all your downloaded EnScripts and either launch them or open the folder where they were found.
By Guidance Software
5491 Downloads
App
Incident Response

EnScript to send file metadata directly to Splunk

EnCase EnScript to send data directly to SPLUNK for IR, Investigations and Timelines.
By Lance Mueller
5044 Downloads
App
Utility

Evidence File Converter

EnScript converts blue-checked EnCase evidence files in the evidence tab to bitstream, dd-type disk images with the option to use the Apple multi-part DMG naming convention.
By Simon Key
6257 Downloads
App
Artifact

EVTX Log Entry Finder

This EnScript finds and bookmarks deleted records from Microsoft Windows EVTX event-log files.
By Simon Key
5345 Downloads
App
Artifact

Exif GPS Information Reader

Search for bookmark and decode Exif metadata with the option to view GPS Exif coordinates in Google Earth automatically.
By Simon Key
7539 Downloads
App
Artifact

Exif Viewer Plugin

The is a self-installing application plugin that enables the user to right-click on an Exif JPEG file in order to view and bookmark the Exif metadata that it contains.
By Simon Key
8394 Downloads
App
Utility

Export and Bookmark Files Based On Extension

Use this EnScript to extract files into separate folders based on extension. The script will create a tab-delimited index file containing the file-system metadata specified by the examiner. Detects and avoids long output paths automatically.
By Simon Key
5907 Downloads
App
Utility

Export by Extension

Export files based on extension
By Lance Mueller
5750 Downloads
App
Utility

Export Result-Set to Project VIC

This script is designed to extract a user-specified result-set to a Project VIC data-set.
By Simon Key
230 Downloads
App
Utility

Extract Bookmarked Items With Bookmark Folder Path

This EnScript extracts selected bookmarked items to a nominated folder whilst preserving the bookmark-folder path. The examiner can opt to extract e-mail records as MSG
By Simon Key
4247 Downloads
App
Artifact

Facebook MSG Finder

This Enscript will find FaceBook artifacts in tagged files and create a detailed bookmark.
By Ryan Jay Ollerenshaw
4640 Downloads
App
Utility

File Block Hash Map Analysis

This EnScript uses block-based hash analysis in order to locate and recover one or more target files in circumstances where other methods are likely to fail.
By Simon Key
5437 Downloads
App
Utility

File Description and Extension Tally

Provides a tally of the total number and size of items with a particular extension or description.
By Simon Key
651 Downloads
App
Utility

File Directory Listing

This EnScript creates a directory listing of all items in the case and makes a .CSV file.
By Joshua Clevenger
5646 Downloads
App
Utility

File Exporter

This program exports files from the current Entry or Results view based upon user selected criteria.
By Karl Winrow
4410 Downloads
App
Utility

File Properties

File Properties is a script to easily cut/paste properties on selected files to your investigation report without using bookmarks.
By Guidance Software
4407 Downloads
App
Utility

File Remediator

FileRemediator uses EnCase's built-in wiping function to target and wipe individual files and folders on a local device and then create all the necessary logs.
By Thomas Plunkett
3730 Downloads
App
Utility

FileHash2SQLite

Map File Hashes to Case Numbers and Examiners using an SQLite database
By Greg Farnham
3854 Downloads
App
Artifact

Find and Parse Prefetch Files in Unallocated

This EnScript searches unallocated clusters for deleted prefetch data. If found, the EnScript will parse out the name of the executable, last run time and run count.
By Lance Mueller
6195 Downloads
App
Utility

Find E-Mail Attachments By Extension

Finds e-mail attachments with file-extensions specified by the examiner. Searches archive attachments (including nested archives) by default.
By Simon Key
6056 Downloads
App
Utility

Find Entries by Hash Category Plus (EnFilter)

This is a modified version of the v7.08 Filter in EnCase to Find Entries by Hash Category
By James Gagen
7430 Downloads
App
Artifact

Find IPV4 Addresses

Finds valid unique IPV4 addresses in ANSI/ASCII and Unicode text-formats.
By Simon Key
3754 Downloads
App
Utility

Find Unique Records by Hash (EnFilter)

This is a modified version of the Filter in EnCase to Find Unique Entries by Hash, I have modified the filter to work on records and will match on the MD5 hash.
By James Gagen
5298 Downloads
App
Utility

Flat File Export

This script is designed to copy tagged items into a single output-folder and report-on user-specified properties in the process.
By Simon Key
2903 Downloads
App
General

Generate ED2K Hash Values

This EnScript will generate ED2K hash values for the purpose of comparing them to some known bad files based on those ED2K hash values.
By Lance Mueller
4408 Downloads
App
Utility

Generic SQLite Database Parser

This script allows one or more pre-defined queries to be run across SQLite database files with names matching those specified.
By Simon Key
977 Downloads
App
Utility

Generic XML Viewer Plugin

Use an extended context-menu option to view and bookmark data contained within XML files.
By Simon Key
4773 Downloads
App
Artifact

GigaTribe Download State Information Finder

The GigaTribe Download State Information Finder searches for information stored whilst a download is progressing on a GigaTribe user’s computer.
By Simon Key
7897 Downloads
App
Artifact

GigaTribe V3 Chat Parser

Locates and parses chat records originating from GigaTribe V3 chat-log files.
By Simon Key
4192 Downloads
App
Incident Response

Hacker Offender

This App is designed to discover files that are hidden by rootkits. It will place all detected files into a LEF for further analysis. This may include the malware and additional files deemed important by the attacker.
By James Habben
6049 Downloads
App
Utility

Has Attachment by Category (EnFilter)

This filter works on Records in email and will return Records with Attachments that match the selected category. The Source of the filter can be viewed to see the changes made.
By James Gagen
4267 Downloads
App
Utility

Hash Calculator Plugin

This EnScript plugin calculates a number of different hash values, either for complete files, or for a range of data. Hash values can be submitted to Virus Total automatically.
By Simon Key
3758 Downloads
App
Utility

Hash List Builder

Generate a matching file set for blue checked items that have had their MD5 hashes processed for import into EnCase Endpoint Security.
By John Lukach
5438 Downloads
App
Utility

Hash List Importer

This EnScript is designed to create a new EnCase hash-library from a list of hashes in tab-delimited format, or from an NSRL hash-set.
By Simon Key
5980 Downloads
App
Artifact

HFS Journal Parser

HFS Journal Parser finds and parses Catalog file record in HFS+/HFSX .journal file.
By Teru Yamazaki
6086 Downloads
App
Artifact

iChat Message Parser

This EnScript parses *.ichat messages of the type created by the Mac OS X Messages application.
By Simon Key
4838 Downloads
App
Artifact

Identify and Extract Date & Time Changes

EnScript to identify 4616 events (date and time change) that exceed a user specified number of minutes allowing the user to quickly discard Time Server syncs.
By Lynette Goh
4195 Downloads
App
Utility

Image Analyzer - 30 Day Free Trial

Free 30 day trial with unlimited image scans – download today and accelerate your investigation. Image Analyzer scans image files within entries and records to identify pornographic content.
By Image Analyzer
145 Downloads
App
Utility

Import Network Nodes Into EE Plugin

Import network hosts and IP ranges from a spreadsheet into the EnCase Enterprise network layout.
By Simon Key
4529 Downloads
App
Reporting

Inventory

Hash and parse all your case files to create an inventory of your cases.
By James Habben
4267 Downloads
App
Utility

Item Ancestor Resolution

This script allows the examiner to identify the ancestors (emails, etc.) of items in a given result-set so they can be bookmarked and/or extracted.
By Simon Key
2723 Downloads
App
Utility

JPEG File Exporter

This app will export tagged jpeg image files and add the jpeg extension to the exported file.
By Ryan Jay Ollerenshaw
4798 Downloads
App
Artifact

JPEGSnoop

View EXIF metadata found in JPEG images within EnCase-- no need for a third-party application to view GPS coordinates, camera make and model, etc.
By Casimer Szyper
6421 Downloads
App
Utility

JSON Viewer Plugin

This EnScript plugin allows the user to view and bookmark application data stored in JavaScript Object Notation JSON files.
By Simon Key
6593 Downloads
App
Reporting

Keyword Search and Proximity Extract

Keyword search and proximity extract is designed to do Fuzzy string extraction by grouping relevant string fragments together.
By Jacques Malan
3571 Downloads
App
Utility

Keyword Search with Range Bookmarking

This EnScript allows the user to perform a raw or transcript keyword search of entries and records, and bookmark a user-specified range of bytes before and after each search-hit.
By Simon Key
4722 Downloads
App
Utility

Known _met Search and Parse

This EnScript will search all tagged items for known.met record fragments from eMule 0.5.
By William Lynn
3912 Downloads
App
Artifact

Link File & Jump List Parser

This EnScript parses recent file-system activity from Microsoft Windows shortcut-link and jump-list files.
By Simon Key
14365 Downloads
App
Artifact

Logon Banner and Text (from SYSTEM registry hive f...

This is an EnScript that extracts and bookmarks the local logon banner and logon text. Verifies corporate policies, such as "further used denotes no expectation of privacy".
By Thomas Hilk
3118 Downloads
App
Utility

Low Hanging Fruit

Low Hanging Fruit Please extracts file name path and MD5 to a SQLite database that also contains an Item Moniker data for each entry.
By John Lukach
5254 Downloads
App
Artifact

Mac OS X AutoLogin Password Decoder

This is a small utility that will decrypt the user-password for a user set to to automatically log-in to a Mac OS X system.
By Simon Key
9472 Downloads
App
Artifact

Mac OS X BinaryCookie File Parser

This script parsers user-specified Mac OS X binary cookie files. Output is by way of bookmarks and a tab-delimited spreadsheet file.
By Simon Key
3892 Downloads
App
Artifact

Mac OS X Log Entry Finder

This script searches user-specified Mac OS X plaintext log-files for log-entries containing one or more keywords.
By Simon Key
5275 Downloads
App
Artifact

Mac OS X OpenBSM Audit Log Parser

This EnScript parses Mac OS X OpenBSM audit-logs, which typically contain details of events relating to audit-control, user-logon and group/user creation/modification/deletion.
By Simon Key
278 Downloads
App
Artifact

Mac OS X Outlook Mail Converter

This EnScript is designed to convert Microsoft Outlook *.olk14MsgSource and *.olk15MsgSource message-files to EML files and a logical evidence file that can be processed by EnCase.
By Simon Key
7536 Downloads
App
Artifact

Mac OS X Previous Versions Chunk Storage Parser

Certain Mac OS X applications support the storage of previous versions of files. This EnScript will recover those files and write them to a logical evidence file so that they can be examined.
By Simon Key
10224 Downloads
App
Artifact

Mac OS X QuickLook Thumbcache Parser

Extracts thumbnail images from Mac OS X QuickLook thumbnail cache files.
By Simon Key
8379 Downloads
App
Artifact

Mac OS X Time Machine Parser

This EnScript allows the examiner to resolve the backup paths of blue-checked files in a Mac OS X Time Machine volume without having to make a copy of the volume available to a Macintosh computer.
By Simon Key
7705 Downloads
App
Utility

MACE Timeline

This script will provide a clean view of computer activity by creating a chronological report of file-system metadata.
By James Habben
5793 Downloads
App
Reporting

Manfreds Berichtsvorlage (NSRL 2.49)

Dieses umfassende Berichtstemplate kann als Basis für Ihre eigene Vorlage dienen. Sie ist sehr umfangreich und enthält Bookmark-Verzeichnisse für die häufigsten Topics Ihrer Untersuchungen.
By Manfred Hatzesberger
3404 Downloads
App
Reporting

Manfred's Comprehensive Case Template

This template may serve you as basis for your own specific template and includes many Bookmark folders for often encountered topics during your exams.
By Manfred Hatzesberger
4594 Downloads
App
Reporting

Manfred's Comprehensive Case Template (NSRL 2.49)

This template may serve you as basis for your own specific template and includes many Bookmark folders for often encountered topics during your exams.
By Manfred Hatzesberger
3347 Downloads
App
Artifact

Matching File Creator

This EnScript allows the examiner to tag items of interest and export a tab-delimited CSV file with the name, MD5 hash value, and logical size of the selected tags.
By Joseph Gaval
3071 Downloads
App
Incident Response

MD5 Malware Database Check

Right click on a selected file to compare it against the VirusToal and/or ThreatExpert databases and determine if it is known malware.
By Guidance Software
925 Downloads
App
Incident Response

MemoryAnalysis

Process Windows, Linux, and OS X memory images and find running processes, parents, create dates, and more.
By Casimer Szyper
8226 Downloads
App
Artifact

Messenger Protocol Fragments

A script to search for protocol fragments of MSN Messenger (or MSN Live Messenger) chat.
By Paul Eric Tew
4964 Downloads
App
General

MFT Date Comparator

This script is designed to identify potentially suspect files by analyzing timestamp differences in the NTFS MFT standard information and filename attributes of each file.
By Simon Key
5175 Downloads
App
Utility

Microsoft Word ASD Document Viewer

This EnScript plugin allows Autosave Document (ASD) files to be extracted and opened with Microsoft Word.
By Simon Key
183 Downloads
App
Utility

Multiple Date Range Filter - Entries Only (EnFilte...

This EnScript filter allows the examiner to show/hide entries using multiple date-ranges and one of four different logic options.
By Simon Key
232 Downloads
App
Incident Response

NETSH Packet Capture

NETSH Packet Capture allows network traffic sniffing on Microsoft Windows 7 and newer machines using natively installed NETSH with a Servlet with Remediation from EnCase Endpoint Security.
By John Lukach
3883 Downloads
App
Reporting

NirSoft ESEDatabaseView Plugin

NirSoft ESEDatabaseView v1.15 executable integration with EnCase for centralized reporting of Extensible Storage Engine (ESE) a.k.a. JET Blue EDB files through the use of bookmarks.
By John Lukach
5190 Downloads
App
Artifact

Nokia Lumia 610 SMS

This script will parse out SMS from a Nokia Lumia 610 mobile phone binary dump.
By Karl Winrow
3452 Downloads
App
Artifact

NTFS $UsnJrnl Parser

This EnScript allows the user to parse valuable information logging NT file-system operations including time files that have been created, deleted and renamed.
By Simon Key
15218 Downloads
App
Utility

Office 2007 Metadata Processor

Reads internal document metadata from Microsoft Office 2007 and later documents.
By Simon Key
728 Downloads
App
Utility

Office 97-2003 Metadata Processor

This EnScript parses metadata from Microsoft Office documents of the format used prior to Office 2007.
By Simon Key
6385 Downloads
App
Utility

OfficeRecovery 2013 Ultimate - Trial Version

Repair and examine the contents of corrupted files in collected evidence. Word Excel digital images and dozens of other formats are supported.
By Recoveronix Software
5044 Downloads
App
General

Old School Search Hit Viewer

The Old School Search Hit Viewer will display search hits in a table; the hits are highlighted with a user-specified amount of context visible around the search hit.
By Kimberly Stone
3889 Downloads
App
Artifact

Outlook PST & OST Deleted File Recovery

This script is designed to recover deleted PST/OST files.
By Simon Key
4085 Downloads
App
Artifact

Parse PE Executable for String Resources

This EnScript specifically targets a resource known as "VS_VERSION_INFO" which contains metadata about the specific executable, including the manufacturer name, original filename, version info and other useful information.
By Lance Mueller
3729 Downloads
App
Artifact

Parse Recent RDP sessions from NTUSER.DAT Files

This EnScript was designed as a "quick hit" to parse and show the MRU values for the Terminal server client for each user.
By Lance Mueller
1015 Downloads
App
Artifact

Parse the setupapi.dev.log of USBs

This EnScript will parse the setupapi.dev.log (Windows Vista/7) for USB connected events and display this in the console tab
By Jordan venderBuhs
6619 Downloads
App
Artifact

Parse Wireless Access Points in Vista, Win7, & Win...

EnScript to extract & display information about wireless networks that have been connected to. Supports analysis of Windows Vista, 7 & 8.
By Lance Mueller
5096 Downloads
App
Artifact

PE Examiner

Parse single or multiple .EXE files and extract all information encoded into the PE (COFF) header. Also works on memory dumps or unallocated space.
By Casimer Szyper
4886 Downloads
App
Artifact

Plist Parser

This EnScript allows the examiner to bookmark and parse multiple Apple property-list (plist) files.
By Simon Key
8599 Downloads
App
Artifact

Plist Viewer Plugin

Use an extended context-menu option to bookmark, decode and extract data contained in Apple property list (.plist) files; automatically view plist files embedded in other plist files.
By Simon Key
10052 Downloads
App
Utility

Pre-Evidence Processing Tasks

Quickly gather needed information before Evidence Processing.
By Tim Taylor
5462 Downloads
App
Artifact

Prefetch Dump (PFDump)

This EnScript parses application usage information stored in Microsoft Windows prefetch files. This version supports Window XP through Windows 10 and includes a run-count and one or more last-run dates.
By Simon Key
10947 Downloads
App
Artifact

Print Spool - SHD & SPL Parser

This EnScript extracts and bookmarks the admin data from the printer shadow files and bookmarks EML print data from the printer spool files.
By Lynette Goh
4905 Downloads
App
Utility

Quick Bookmark Folders

Quickly make bookmark folders for each device in your case. Automate making bookmark folders and subfolders for each device in your case. Along with bookmarking each device and each volume in the case. User configurable subfolders.
By Brett Liddicoet
3571 Downloads
App
Artifact

RDP Cached Bitmap Extractor

This EnScript parses bitmap data cached by the Microsoft Windows Terminal Services (Remote Desktop Protocol - RDP) client.
By Simon Key
5036 Downloads
App
Utility

Record to Excel

Use Record2Excel to export records to Microsoft Excel. This script works with any records list which can be tagged. It will export all record properties (fields values) to Excel. Requires Microsoft Excel.
By Guidance Software
3646 Downloads
App
Artifact

Registry Files Exporter

Export Windows Registry files from Windows OS
By Isaac Lee
6147 Downloads
App
Utility

Registry Viewer Plugin

This script allows the examiner to to use a right-click context-menu-option or keyboard shortcut to view Registry hive files (SYSTEM, SOFTWARE, SECURITY, SAM, NTUSER,DAT, etc.).
By Simon Key
1641 Downloads
App
Utility

RegRipper Launcher

This EnScript runs RegRipper directly from EnCase. Automatically bookmark results or load them in a Micorsoft Word / Open Office document. Requires RegRipper.
By Guidance Software
996 Downloads
App
Utility

Remote Agent Deployment

This EnScript allows the user to remotely deploy agents across their enterprise.
By Guidance Software
4184 Downloads
App
Utility

Retention Analyzer

Calculates the volume based on logical size in bytes per month based on MAC times for an eight year time frame that are not tagged as 'Known'.
By John Lukach
3654 Downloads
App
Utility

Run Condition As Filter

This download consists two filters designed to make it easier to locate, edit, and launch conditions from multiple locations. They also make it easier to create modified copies of the conditions that ship with EnCase.
By Simon Key
591 Downloads
App
Artifact

Safari Evidence Processor Module

This is a self-installing Evidence Processor module that parses macOS Safari web-browser data.
By Simon Key
5876 Downloads
App
Utility

Safari Form Values Decryptor For Windows (SFVDWIN)

Use this tool to extract the autofill form values from the encrypted Form Values plist that Safari uses. It requires the user’s keychain and associated password to decrypt the data.
By Simon Key
7796 Downloads
App
Utility

Search and Bookmark Specific Data Types

This EnScript allows the examiner to search for one or more keywords and bookmark the resultant search-hits using specific data-types (picture, ROT13, low ASCII, hex, etc).
By Simon Key
7195 Downloads
App
Artifact

Search For Valid Bitcoin Addresses

This EnScript searches entries and records for valid BitCoin addresses.
By Simon Key
3640 Downloads
App
Utility

Search Hits Preview

This EnScript creates a search hit preview file that can be imported into Excel.
By Ryan Jay Ollerenshaw
3225 Downloads
App
Artifact

SEEB USB - Mounted Devices Report

Script will create detailed Excel, CSV, console & bookmark reports on Mounted, USB, portable devices found in the registry and setupapi logs.
By Brian Jones
8546 Downloads
App
Artifact

ShellBags Parser

Parses recent-folder view settings maintained by the Microsoft Windows operating system.
By Simon Key
1169 Downloads
App
Artifact

ShimCache Parser

This EnScript mounts all SYSTEM registries found in the current evidence, parses the Application Compatility Cache registry key and output the result onto the console, bookmarks and tab-delimited CSV file.
By Isaac Lee
5409 Downloads
App
Utility

Show or Hide Items with a Selected Tag

This Filter will enable the user to show or hide items based on the tag status.
By James Gagen
3366 Downloads
App
Utility

SimpleSearch

This EnScript searches for keywords in every open case and bookmarks the files.
By Iosif Dan Laszlo
4502 Downloads
App
Artifact

Skype Chatsync IP Addresses

This EnScript will parse out the IP addresses from Skype chatsync files and write them to the console as well as bookmark the artifacts.
By Lance Mueller
5386 Downloads
App
Utility

SQLite Blob Extractor

This script is designed to extract BLOB-data from SQLite database files.
By Simon Key
1640 Downloads
App
Artifact

SQLite Free-Page Parser

This EnScript is designed to read and decode unused pages from SQLite database files, pages which may contain deleted data.
By Simon Key
2185 Downloads
App
Utility

SQLiteQuery

Allows SQL querying of all SQLite databases from within EnCase.
By Doug Collins
4705 Downloads
App
Utility

Startup Manager

Startup Manager lets you select EnScripts and EnPacks to start automatically when EnCase starts.
By Carmona Pereyra
3778 Downloads
App
Utility

System Snap Shot

System Snap Shot collects information regarding software used, system settings, user names, last login information, and connections made that would allow data to be moved off the machine.
By Jordan venderBuhs
3474 Downloads
App
Artifact

SysTools Outlook Exporter v2.2 (Demo Version)

SysTools Outlook Exporter is an EnCase plugin which allows you to export email evidence found with EnCase forensic to an Outlook (.pst) file WITHOUT Outlook.
By SysTools Software
3371 Downloads
App
Incident Response

Team Cymru Malware Hash Registry Search

Review evidence files to assist in learning if any might correspond to malware.
By Jeffrey Savoy
5800 Downloads
App
Incident Response

ThreatAnalyzer Automation Toolkit

ThreatAnalyzer provides best in class dynamic file analysis which enables the investigator to quickly determine any behaviors a given file sample may exhibit.
By Cisco Systems
3700 Downloads
App
Utility

ThreatGRID Malware Analysis and Intelligence for E...

Threat Grid Malware Analysis and Intelligence for EnCase® provides direct integration with Threat Grid, the first unified malware analysis and threat intelligence solution. Threat Grid provides in-depth analysis and correlates attack-related artifacts.
By Cisco Systems
5251 Downloads
App
Artifact

Thumbcache Parser

This script parses the thumbcache_*.db files used to store thumbnail images generated as a result of viewing pictures in Windows Explorer under Windows Vista, 7, 8/8.1 and 10.
By Simon Key
4739 Downloads
App
Artifact

Timezone Info Prior to Processing

This EnScript allows the Examiner to determine the timezone settings of each device prior to running the EnCase Evidence Processor.
By Jamey Tubbs
5929 Downloads
App
Reporting

Umfassende Berichtsvorlage

Dieses umfassende Berichtstemplate kann als Basis für Ihre eigene Vorlage dienen. Sie ist sehr umfangreich und enthält Bookmark-Verzeichnisse für die häufigsten Topics Ihrer Untersuchungen.
By Manfred Hatzesberger
3448 Downloads
App
Utility

UNC Path Preview and Acquire

Use this script to preview the files and folders on a remote share using a UNC path. Specific user credentials can be supplied where necessary.
By Simon Key
7797 Downloads
App
Utility

Unmount Compound File

This will add a right click option to unmount a compound file. This can be used to try a different password or just get rid of the additional items.
By James Habben
4001 Downloads
App
Artifact

User Assist Registry Value Decoder

Decodes data used by the Microsoft Windows operating system to populate each user's start menu with frequently used applications.
By Simon Key
887 Downloads
App
Utility

UsnJrnl Record Keyword Search and Export to CSV

This script will prompt for a keyword from the user then search selected tagged items for that keyword.
By William Lynn
4855 Downloads
App
Utility

Utilities (aka Last Folder) Plugin

This is a utility plugin making it easier to open folders used for output, create index queries, and select emails containing notable attachments (or vice versa).
By Simon Key
7971 Downloads
App
Utility

Video Split

This EnScript uses Ffmpeg to create thumbnail images from selected movies. The images are automatically made into a LEF file which can then be added to a case.
By Guidance Software
3623 Downloads
App
Utility

View SQLite With WAL Plugin

Allows SQLite database files to be opened in conjunction with any write-ahead log (WAL) file.
By Simon Key
670 Downloads
App
Incident Response

VirusShare.com Contextual Data

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts samples of malicious code.
By John Lukach
3612 Downloads
App
Incident Response

VirusShare.com Hash Library

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts samples of malicious code.
By John Lukach
5005 Downloads
App
Incident Response

VirusShare.com Hash Sets

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts samples of malicious code.
By John Lukach
4879 Downloads
App
Incident Response

VirusTotal Bookmark

This EnScript provides a quick automated way to tag files and then automatically submit their hash values to Virus Total for analyzing.
By Lance Mueller
3788 Downloads
App
Utility

Volatility Plugin

This EnScript is designed to facilitate easier use of Volatility in EnCase. It can be configured for any number of Volatility plugins and supports multithreading.
By Simon Key
1249 Downloads
App
Incident Response

Volatility Reporting Plugin

Volatility 2.4 Standalone executable integration with EnCase for centralized reporting of memory forensic results through the use of bookmarks.
By John Lukach
5769 Downloads
App
Artifact

VSS Examiner

Quickly and easily identify and preserve data of interest in Microsoft Windows volume shadow copies.
By Simon Key
16898 Downloads
App
Artifact

WebCacheV01.dat Internet History Decoder

This EnScript parses Internet history data from WebCacheV01.dat files. This includes the Internet history data generated by the Microsoft Internet Explorer and Edge web-browser programs.
By Simon Key
10416 Downloads
App
Artifact

Webpage Rebuilder

This script will export and rebuild tagged records into a local file to view with a browser.
By James Habben
5991 Downloads
App
General

What's New In App Central

This EnScript will find any new or updated EnScripts at EnCase App Central.
By Guidance Software
4554 Downloads
App
Artifact

Windows 8 and 8.1 Mail Finder

Finds deleted e-mail messages originating from the Windows 8 and 8.1 Mail applications.
By Simon Key
3621 Downloads
App
Artifact

Windows Device Properties Parser

This script parses extended device-property information from Microsoft Windows SYSTEM Registry hive files.
By Simon Key
631 Downloads
App
Utility

Windows Drive Letter Assignments

This EnScript is designed to identify Windows drive-letter assignments for volumes in the current case that have been identified as originating from fixed disks.
By Simon Key
11475 Downloads
App
Artifact

Windows Event Log Export

This EnScript searches for pre-vista event log files (*.evt) and checks if they are flagged dirty.
By James Habben
6164 Downloads
App
Utility

Windows Executable Packer Detection

Analyze Windows executables and detect modification by a packer or cryptor.
By James Habben
6112 Downloads
App
Artifact

Windows Installed Application Parser

Parses installed-application information and displays it in a manner similar to Microsoft Windows.
By Simon Key
3388 Downloads
App
Artifact

Windows Live Mail to MBOX Converter

This script converts a Windows Live Mail e-mail store to a sequence of MBOX files in a logical evidence file that can be added to a case and processed in the usual way.
By Simon Key
7453 Downloads
App
Utility

Windows Quick View Plugin

This is an EnScript plugin that allows the examiner to quickly open evidence-items using the default Windows viewer.
By Simon Key
4341 Downloads
App
Artifact

Windows Search Application Data Parser

This script parses data maintained by the Windows search function relating to recently-used applications and documents
By Simon Key
743 Downloads
App
Utility

ZIP Index Entry Finder

This EnScript will search for, and bookmark, ZIP-file index-entries. It was designed for the recovery of data from deleted ZIP files that can't otherwise be recovered, either because they're partially overwritten or fragmented.
By Simon Key
3088 Downloads
App