OpenText EnCase Enterprise is a digital forensic platform that enables investigators to remotely acquire, preserve, and analyze evidence from endpoints across a network. The software creates forensically sound images of both persistent storage and volatile system memory, maintaining a chain of custody through verification hashing. Its capabilities include recovering deleted files, parsing various file systems and operating system artifacts like the Windows registry, and analyzing data from email stores and internet activity. Investigators can perform keyword and indexed searches, conduct timeline and hash analysis, and use file signature analysis to identify disguised files. The platform allows for bookmarking findings, organizing artifacts within a case structure, automating tasks with the EnScript language, and generating detailed reports.