Remote forensic data acquisition across the network: EnCase Enterprise uses a deployed servlet to reach endpoints across the network, allowing investigators to acquire data from remote systems without physically seizing them, which is essential for enterprise-scale and covert investigations.
02
Disk and memory imaging: The platform creates forensic images of storage devices and can capture system memory, preserving both persistent and volatile evidence in a forensically sound manner.
03
Forensic analysis of evidence (file systems, artifacts): EnCase parses a wide range of file systems and operating-system artifacts, reconstructing files, folders, and system activity so investigators can examine the contents and history of acquired evidence.
04
Keyword and indexed searching: Investigators can run keyword searches and build indexes across evidence to rapidly locate relevant terms and content within large data sets.
05
Email and internet artifact analysis: The tool extracts and analyzes email stores and internet activity such as browser history, cache, and downloads, surfacing communications and web behavior relevant to a case.
Your plan caps how many capabilities are shown — upgrade to see the full list