This article can also be found in the Premium Editorial Download "Information Security magazine: Top forensics tools for tracking down cybercriminals."

Download it now to read this article plus other related content.


Guidance Software's EnCase
Guidance Software has long been the leader in forensics software with EnCase, the most-used forensics acquisition and analysis tool by law enforcement and the private sector.

EnCase has ample court history to support its usability, and it supports the acquisition of evidence from just about every operating system, file system and media type, including live systems. Through what Guidance calls a passive agent, it performs over-the-network acquisition of evidence from live systems to a remote analysis station. EnCase then creates well-organized, detailed reports that are understood by experts and attorneys alike.

EnCase images hard drives and partitions via a proprietary format in which equal-sized chunks of information are read from the source media and then written to the destination, along with an accompanying hash for data integrity. This serves as an integrity check--the benefit being the rapid reacquisition of data should any chunk's hash fail the check.

For searching, EnCase employs an extremely flexible Unix grep-like facility. These searches, which take time but yield valuable results, parse evidence byte by byte and can uncover deleted files and other non-file data.

Though its enterprise edition is more expensive than the other tools listed here, EnCase Enterprise also offers additional features such as network-based acquisition.

AccessData's Ultimate Toolkit

    Requires Free Membership to View

AccessData's Ultimate Toolkit (UTK) incorporates a password recovery tool capable of decrypting just about any file, an enhanced registry viewer designed to illuminate evidence hidden in system-only accessible registry keys, a disk wiper and a distributed-computing en-cryption breaker.

UTK's edge is its database-driven architecture. As evidence is imported (typically drive and partition images), it's scanned and indexed into a case database. This allows for quick ad hoc string queries and organization of extracted files and data without the need to rescan. This same type of search performed by other products can take considerable time; UTK returns instantaneous results.

This was first published in December 2005

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: