ISDF Encase Forensic
ISDF Encase Forensic
Experiment No.: 6
Objectives:
1. Data Collection and Preservation: Acquire and preserve digital evidence from
various storage devices without altering the original data, ensuring integrity.
2. In-Depth File and Activity Analysis: Recover deleted files, analyze file systems,
and investigate user activity (emails, internet history) to uncover hidden or relevant
evidence.
3. Efficient Searching and Reporting: Conduct keyword searches across the data and
generate detailed reports for legal or investigative purposes.
CO .
1. https://www.opentext.com/products/encase-forensic
2. https://e-forensic.ca/products/encase-forensic-suite/
3. https://en.wikipedia.org/wiki/EnCase
Related Theory:
1. Forensic Imaging:
The process of creating a bit-by-bit copy of a storage device (e.g., hard drive,
USB) to ensure the original evidence remains intact while enabling analysis.
This concept emphasizes data integrity and ensuring no alterations occur during
the acquisition process.
2. Chain of Custody:
A key legal principle in digital forensics that tracks the handling of evidence
Implementation details:
1. Create New Cases
Open EnCase and Launch the EnCase application on your system.
4. Add Evidence:
• After the case is created, you can add evidence by clicking "Add Evidence".
• You can add forensic images, physical drives, or logical evidence files.
• Detail of Evidence
• Image Evidence
• Process Option
• Block View
• Gallery view
• Timeline view
• Artifacts
• Bookmarks
• TO VIEW BOOKMARKS
• Write Block
Conclusion: