Over the years, digital investigators using EnCase have become intimately familiar with EnCase status reporting for EnScripts and in recent years, Evidence Processor. Over the years, progress reporting in EnCase has more or less, looked like this:
Evidence Processor Performance Monitoring - Part I
Over the years, digital investigators using EnCase have become intimately familiar with EnCase status reporting for EnScripts and in recent years, Evidence Processor. Over the years, progress reporting in EnCase has more or less, looked like this:
How Does Integration Help You as an Investigator?
A new IEF/EnCase Processor Module will be available September 12th.
The IEF/EnCase Connector referenced in the Blog is available here.
Let’s imagine I have been assigned to investigate case involving an employee who is suspected of posting threatening comments on a co-worker’s Facebook account (this could either be an internal employee misconduct or criminal investigation). The messages were sent yesterday.
- Posted by: Miller
- On: 8/26/2013
- No comments
- Categories: EnCase App Central , EnCase Forensic , Integration , Internet Evidence Finder
Windows Resilient File System Forensics
In the fall of 2012, Microsoft made Windows Server 2012 generally available with a quietly announced feature: Resilient File System (ReFS). Of course, Microsoft does not roll out new file systems casually, and when they do, the ripple effects are generally felt slowly. NTFS has been generally available since Windows NT 3.1, released in 1993. If one runs a data center of any size, swapping out the underlying file system of critical or precious data is not a decision taken lightly. In large part, this justifies a general complacence in our field of digital forensics tools when considering how to deal with this new file system. Today, ReFS is a rare bird: investigators just don’t see it very often. We think that is going to begin to change later this year.
Volatility Reporting Plugin for EnCase Forensic v7
As most investigators know, volatile memory contains valuable information about the runtime state of the system, registry keys, network connections in memory and much more. One of the most popular tools to handle memory analysis is Volatility, an open source tool created by Volatile Systems.
- Posted by: Miller
- On: 8/07/2013
- No comments
- Categories: EnCase App Central , EnCase Forensic , Memory Analysis , Volatility
EnCase App Central - Destined To Be A Game Changer
We are all painfully aware that criminals share their secrets, exploits and even technology. Those investigating cybercrime, attempting to pre-empt dangerous criminals, or finding new ways to rapidly clear cases must be on equal footing.
Whether on the desktop, server, smart mobile device, cloud or on a network, investigating cybercrime requires a combination of exceptional tools along with expert knowledge. One of the unique elements of investigating cybercrime efficiently is that you need expertise in both computer science and social science. Unfortunately, there has not been a solid methodology to bring this cross domain expertise to fruition. It is vital that we close this gap and create a greater overlap between these domains.