The powerful and efficient features in EnCase® Enterprise have made it the trusted standard for digital investigations. No other product offers the same degree of functionality, acceptance, and performance.
Acquire from Almost Anywhere
Acquire data from disk or RAM, documents, images, email, webmail, internet artifacts, web history and cache, HTML page reconstruction, chat sessions, compressed files, backup files, encrypted files, RAIDs, workstations, servers, and—with Version 7—smartphones and tablets.
Complete Endpoint Visibility
View hundreds of file formats in native form or with a built-in registry viewer, process and system information viewer, and integrated photo viewer, or see results on a timeline/calendar.
Forensically Sound Acquisition
EnCase Enterprise produces an exact binary duplicate of the digital evidence, then verifies it by generating MD5 hash values for related image files and assigning CRC values to the data. These checks and balances reveal when evidence has been tampered with or altered, helping to keep all digital evidence forensically sound for use in court proceedings or internal investigations.
Recover files and partitions, detect deleted files and password-protected files, perform file signature analysis and hash analysis--even within compounded files or unallocated disk space.
Preview results while data is being acquired. Then, once your image files are created, you can search and analyze multiple drives or media simultaneously. Enhanced caching capabilities have been designed to give you instant access to case data--even if the machine is offline.
Automated de-NISTing Capabilities
The National Software Reference Library (NSRL) is provided in the EnCase hash library format, making it easy to de-NIST potential evidence, eliminating thousands of known files from your evidence sets. This significantly reduces the time and amount of data to be analyzed.
Customizable and Extensible with EnScript
EnCase Enterprise features extensibility via EnScript® programming capabilities. EnScript® lets you create to custom scripts to help automate time-consuming investigative tasks, such as searching and analyzing specific document types or other labor-intensive processes and procedures. You can harness this power to greatly improve efficiencies around tasks unique to your organization.
Export reports with lists of relevant system information, files, and folders along with detailed list of URLs, with dates and time of visits. Provide hard-drive information and details related to the acquisition, drive geometry, folder structure, etc.
Once you’ve identified relevant evidence, you can create a comprehensive report for presentation in court or to management and other stakeholders in the outcome of the investigation.
Supports Compliance Initiatives
EnCase Enterprise Version 7 facilitates the investigative requirements of several regulatory mandates including Sarbanes-Oxley, HIPAA, and GLBA.
Common processes, including custom EnScript programs, can be automated, allowing you to improve your efficiency. With template-driven processing, your results are consistent, providing output that’s easy to find and use.
Optimized and Integrated EnScript®
Investigators with heavy case workloads appreciate the efficiencies added by additional automation via EnScript®. We've added the ability to integrate custom EnScript results in to the Evidence Processor as well as vastly improved performance. Windows 7 artifacts are supported now, as well.
Our robust new query language uses an advanced index engine to search across entire cases at once, enabling swift identification of potential evidence.
Intuitive User Interface
We've completely overhauled the user experience and created a new, easy-to-use, tabbed interface that might remind you more of a web-browsing experience.