EnCase Forensic v7.03 Onesheet Rev

Published on September 2016 | Categories: Documents | Downloads: 125 | Comments: 0 | Views: 257
of 2
Download PDF   Embed   Report

Comments

Content

GUIDANCE SOFTWARE | EnCase Forensic v7

What’s New in EnCase® Forensic v7.03
Digital Investigations just got easier

EnCase® Forensic v7 introduced a new approach to digital investigations. In v7.03, the
transformation continues. The new capabilities in v7.03 will make completing your investigations
more efficient than ever before.

Stand-Alone EnCase® Processor License Now Included
The EnCase Processor is a new product designed with one purpose in mind – the acquisition
and processing of evidence. The stand-alone EnCase Processor gives organizations the ability
to dedicate a computer or computers solely to processing evidence. With this added capability,
organizations can build up a backlog of processed evidence ready and waiting for investigation.
The stand-alone EnCase Processor will increase productivity and efficiency for any organization.
Best of all, one EnCase Processor license is now included with all licenses of EnCase Forensic
v7 at no additional charge.

EnCase Review Package
The EnCase Review Package is an easy way for forensic examiners to share their findings with
detectives, D.A.s, field agents or anyone else interested in the case. But sharing evidence is only
part of the benefit.
With the review package, others who are not forensic specialists can review evidence, tag files,
and send their review results back to the forensic examiner to be incorporated into the case. For
instance, if the examiner discovers e-mails in German, the examiner can create a review package
for the e-mails, provide it to a translation specialist, and easily incorporate the translator’s review
results back into the case.
The EnCase Review package saves time by providing visibility into the evidence to a wide range
of people, allowing the examiner to complete investigations faster. The EnCase Review Package
is included in EnCase Forensic v7.03 at no additional charge.

EnCase Evidence Processor Enhancements
There are a number of valuable enhancements to the Evidence Processor in v7.03. First, the
processing of evidence has been increased significantly, resulting in evidence files being
processed significantly faster than in v7.03. The performance increase includes processing
additional artifacts in 7.03, such as unallocated space, Google Chrome Internet history, USB,
mapped and shared drive artifacts.

Processing Devices from a Local Preview
The EnCase Evidence Processor now processes devices from the Local Preview which allows
you to bypass acquiring these devices and directly process the evidence.

Support for Indexing Text in Slack and Unallocated Space
EnCase Forensic now supports indexing text in slack bytes and unallocated space. As you select
options for indexing within the Evidence Processor, you can choose to include text identified in
file slack and unallocated space.

Evidence Processor System Info Includes NetShare and USB Registry
Now the Evidence Processor can search NetShare and USB registry information in the
Records tab. With this capability users can see the UNC path visit history, the history of
connected devices, and then can correlate USB devices to their drive letters.

www.guidancesoftware.com

GUIDANCE SOFTWARE | EnCase Forensic v7

New Software and File System Support
Version 7.03 introduces support for the following software and file systems



Google Chrome
EXT4 Linux Software RAID Arrays (Ubuntu Version 9.1 and 10.04)

Updated Encryption Support
EnCase Forensic v7.03 allows users, with the appropriate credentials, to acquire and perform investigations on devices using any of the following
encryption products.

Vendor

Product

Supported Versions

64-bit Support

Check Point

Check Point Full Disk Encryption (Formerly Pointsec PC)

6.3.1 up to 7.4

Yes

CREDANT

Mobile Guardian

5.2.1, 5.3, 5.4.1, 5.4.2, 6.1 through 6.8

No

GuardianEdge

Encryption Plus/Anywhere

7 and 8

No

GuardianEdge

Hard Disk Encryption

9.2.2, 9.3.0, 9.4.0, 9.5.0, 9.5.1

Yes

McAfee

SafeBoot

4.5, 6

No

Microsoft

BitLocker and BitLocker To Go

Vista, 7

Yes

Sophos

SafeGuard Easy (Formerly Utimaco)

4.5

Yes

Symantec

PGP Whole Disk Encryption

9.8, 9.9, 10

Yes

Symantec

Endpoint Encryption

7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 8.0

Yes

WinMagic

SecureDoc Full Disk Encryption

4.5, 4.6

No

Our Customers
Guidance Software’s customers are corporations and government agencies in a wide variety of industries,
such as financial and insurance services, technology, defense contracting, pharmaceutical, manufacturing
and retail. Representative customers include Allstate, Chevron, FBI, Ford, General Electric, Honeywell,
NATO, Northrop Grumman, Pfizer, SEC, UnitedHealth Group and Viacom.
About Guidance Software (NASDAQ: GUID)
Guidance Software is recognized worldwide as the industry leader in digital investigative solutions.
Its EnCase® platform provides the foundation for government, corporate and law enforcement
organizations to conduct thorough, network-enabled, and court-validated computer investigations of
any kind, such as responding to e-discovery requests, conducting internal investigations, responding
to regulatory inquiries or performing data and compliance auditing - all while maintaining the integrity
of the data. There are more than 40,000 licensed users of the EnCase technology worldwide, the
EnCase® Enterprise platform is used by more than sixty percent of the Fortune 100, and thousands
attend Guidance Software’s renowned training programs annually. Validated by numerous courts,
corporate legal departments, government agencies and law enforcement organizations worldwide,
EnCase has been honored with industry awards and recognition from Law Technology News, KMWorld,
Government Security News, and Law Enforcement Technology.
©2012 Guidance Software, Inc. All Rights Reserved. EnCase and Guidance Software are registered trademarks or trademarks owned by
Guidance Software in the United States and other jurisdictions and may not be used without prior written permission. All other marks and brands
may be claimed as the property of their respective owners. Passware Kit Forensic is a registered trademark owned by Passware.

www.guidancesoftware.com

EF FS 1111-50023

Sponsor Documents

Or use your account on DocShare.tips

Hide

Forgot your password?

Or register your new account on DocShare.tips

Hide

Lost your password? Please enter your email address. You will receive a link to create a new password.

Back to log-in

Close