From the simplest requirements to the most complex,
EnCase® Forensic is the premier computer forensic application on the market. It gives
investigators the ability to image a drive and preserve it in a forensic manner using the EnCase
evidence file format (LEF or E01), a digital evidence container validated and approved by courts
worldwide.
EnCase Forensic also contains a full suite of analysis,
bookmarking and reporting features. Guidance Software and third party vendors provide support for
expanded capabilities to ensure that forensic examiners have the most comprehensive set of
utilities.
EnScripts and
customizable filters allow examiners of all experience levels can quickly parse out relevant data
for further review with pre-built EnScripts or by developing their own EnScript tools.
EnCase Forensic also offers powerful hidden volume detection
and volume rebuilding capabilities, allowing investigators to review evidence that would have been
irretrievable with other computer forensics applications.