Chapter 6 Guidance Software’s EnCase

DOI: 10.1201/9781003134817-6

Please keep in mind here that the goal is not to show you all the different things EnCase can do. The focus here is on showing you how to use EnCase to solve the same case we just covered with AccessData’s forensic tool. Again, the version of the tool you use may be different than the one I am using and as such could look different.

Note that you can acquire evidence (bitstream backup) on any computer that is running Microsoft Windows or the DOS operating system; however, you can analyze the evidence files only on computers running one of the following operating systems; i.e., the evidence files must be placed on one of the following types of systems: Windows 98, Windows ME, ...

Get Cyber Crime Investigator's Field Guide, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.