SANS Product Review - EnCase Forensic 8.06

Publication
13 Pages

Download pdf

SANS Instructor Jake Williams (@malwarejake) reviews EnCase Forensic 8.06, its features, and tests its capability to analyze digital forensic data. In this evaluation, SANS specifically evaluated the following features, each of which are covered in-depth in this paper:

  • Acquisition of forensic data features, including device acquisition and direct network preview
  • Productivity and workflow features, including pathways, indexing, keyword searching, EnScripts and App Central, and 4th pane
  • Evidence processor features, including prioritization, entropy analysis, email processing, and internet artifact processing

Related Topics:
Internal Investigation, Criminal Investigation

Related Products:
EnCase Forensic