New with Version 7: EnCase Review Package, Faster Processor and More
The powerful and efficient features of EnCase Forensic have made it the trusted standard in corporate and criminal investigations, as well as in courts around the world. No other product offers the same degree of functionality, court acceptance, and performance.
Intuitive User Interface
A redesign of the user experience has resulted in an easy-to-use tabbed interface that may remind you of your favorite web browser.
Share Your Findings with Ease
The EnCase Forensic Review Package lets you share findings with other people involved with your case, including detectives, district attorneys, field agents, and fellow investigators.
Tablet and Smartphone Acquisition
Acquire data from most popular smartphones and tablets and easily integrate the results into cases.
Simple E-Mail Review
Understand the context of email-based potential evidence with threading and related conversations for context.
Now you can use custom EnScripts to automate common processes, which can greatly increase your efficiency. Template-driven processing results are consistent, providing easy-to-find, easy-to-use output.
New Evidence Processor
The new indexing engine gives our re-engineered evidence processor more powerful queries and faster processing, plus the ability to automate tasks, create templates based on case profiles, and readily integrate EnCase Forensic results.
Broadest File-Type and OS Support Anywhere
No other product delivers the broad file-type and operating-system (OS) support of EnCase Forensic. With Version 7, you also get EnCase® Decryption Suite, EnCase® Physical Disk Emulator, EnCase® Virtual File System, and EnCase® FastBloc SE.
Acquisition from Almost Anywhere
Acquire data from disk or RAM, documents, images, email, webmail, Internet artifacts, web history and cache, HTML page reconstruction, chat sessions, compressed files, backup files, encrypted files, RAID workstations, servers, and--with Version 7--smartphones and tablets.
Uncover critical evidence using advanced search capabilities to identiy data that would be irretrievable with other computer forensic applications.
Begin reviewing results while data is being acquired. Once image files are created, search and analyze multiple drives or media simultaneously.
Automated De-NISTing Capabilities
The National Software Reference Library (NSRL) is provided in the EnCase hash library format, letting you easily de-NIST your potential evidence, eliminating thousands of known files from your evidence set.Court-Accepted
EnCase Forensic preserves data in an evidence file format (LEF or E01) with an unsurpassed record of court acceptance.Customizable and Extensible with EnScript®
EnScript, an object-oriented programming language similar to Java or C++, lets you create custom programs to automate time-consuming investigative tasks, such as searching and analyzing specific document types or other labor-intensive processes.Automatic, Customizable Reports
Easily create custom report templates that produce consistent, professional reports for every type of case, then export with lists of all files and folders along with a detailed list of URLs and dates and times of visits to each. EnCase Forensic Reports provide hard-drive information and details related to the acquisition, drive geometry, folder structure, and more.Forensically Sound
EnCase Forensic produces an exact binary duplicate of the original drive or media, then verifies it by generating MD5 hash values for related image files and assigning CRC values to the data. These checks and balances reveal when evidence has been tampered with or altered, helping to keep all digital evidence forensically sound for use in court proceedings or internal investigations.Integration to Passware Kit Forensic
Use the Evidence Processor to automate the detection of encrypted files. Once the files are decrypted by Passware Kit Forensic, they can be easily integrated back into EnCase Forensic for further analysis. (Passware Kit Forensic license sold separately. Contact Sales
for more information.)