Forensic Tools and Techniques - EnCase & XRY

Authors Avatar by tsothcott (student)

Contents

Section 1 – Forensic Software Evaluation        

Section 2 – Forensic Software Portfolio        

Bibliography        

        

Section 1 – Forensic Software Evaluation

Encase by Guidance Software
EnCase by Guidance Software is an industry-standard computer investigation solution. It provides forensic practitioners with useful features to assist them with efficient, forensically sound data collection and investigation using a repeatable process. EnCase provides useful tools for data acquisition, file recovery and indexing/search file parsing.

Two major features that EnCase boasts are the range of operating systems and file systems supported. Each operating system contains a different amount of file systems which the operating system utilises. It is useful to have this feature available to examiners due to the fact that there are many different electronic devices running these different Operating Systems and file systems. For example, EnCase provides support for Smartphone and Tablets running the following operating systems; Apple iOS, Android OS, Blackberry OS, Palm OS, Symbian and Windows Mobile OS. EnCase also organises files in a sensible and logical order. For example, it creates a directory for evidence files, which contains only the files or folders needed. Another feature of the data acquisition process is the Cyclical Redundancy Checksum (CRC) hash. Each image created with EnCase will produce both a CRC and a MD5 hash for future integrity. Following this, EnCase also provides the option to encrypt the evidence with a secure SHA

Forensic Examiners will often also need to require evidence off a live machine, so EnCase provides a feature called the ‘WinEN’ utility. This allows them to collect evidence from Random Access Memory (RAM). In other cases, an examiner may need to boot up a system in a ‘live state’ in order to recover evidence. However, doing so has the possibility to contaminate evidence, so EnCase provides another useful utility called the ‘LinEn’ utility which allows the examiner to boot the device in a forensically sound manner.

Join now!

EnCase provides a series of automation tools which helps speed up the investigation process. One major automation features is the use of ‘EnScripts’ – custom or pre-defined scripts used in data carving to find specific bits of data. These scripts are useful, for example, in a fraud case. The examiner would be able to setup a script to automatically filter out anything related to fraud, credit cards, bank details etc. Another automation feature is the use of Filters and Conditions, which again, helps narrow down data to a specific rule. These can also be bound together in a series of ...

This is a preview of the whole essay