Professional Documents
Culture Documents
INFT
3031
PRACTICAL
01
ENCASE
FUNDAMENTALS
CREATING
A
CASE
ADDING
EVIDENCE
TO
A
CASE
NAVIGATING
ENCASE
FORENSIC
Academic Program
PRACTICAL 1.1
CREATING A CASE
Case
Management
One
of
the
most
powerful
features
of
EnCase
soware
(EnCase)
is
its
ability
to
organise
dierent
types
of
media
together,
so
that
they
can
be
searched
as
a
unit
rather
than
individually.
This
process
saves
me
and
allows
the
examiner
to
concentrate
on
examining
the
evidence.
In
such
a
case,
the
evidence
les
should
be
placed
on
a
central
le
server,
and
copies
of
the
case
le
should
be
placed
on
each
invesgators
computer
(since
case
les
cannot
be
accessed
by
more
than
one
person
at
a
me).
3
Case
Management
The
Encase
Forensic
methodology
strongly
recommends
that
the
examiner
use
a
second
hard
drive
or
at
least
a
second
paron
on
the
boot
hard
drive
for
the
acquision
and
examinaon
of
digital
evidence.
It
is
preferable
to
wipe
an
enre
hard
drive
or
paron
rather
than
individual
folders
to
ensure
all
of
the
temporary,
suspect-related
data
is
destroyed.
This
will
aid
in
deecng
any
claims
of
cross-contaminaon
by
the
opposing
counsel
if
the
forensic
hard
drive
is
used
in
other
cases.
4
Case
Management
One
method
of
organisaon
is
to
create
a
folder
for
each
case
and
to
place
the
associated
case
le
and
evidence
les
in
that
folder.
Reports
and
evidence
copies
can
then
be
placed
in
the
same
folder
or
in
subfolders.
Case
Management
Before
we
create
a
new
case
in
Encase,
we
will
create
a
folder
structure
(as
outlined
on
the
previous
slide)
for
our
case.
Create
a
Cases
folder
on
your
Desktop
and
a
Barrow
subfolder
for
our
case.
Within
the
Barrow
subfolder,
create
the
four
new
folders:
Evidence
Export
Index
Temp
Case
Management
Start
EnCase
and
select
File
New
or
click
on
the
New
icon
on
the
toolbar.
The
Case
Opons
dialog
box
will
appear.
Enter
Barrow
as
the
Name
and
your
inials
as
the
Examiner
Name.
Select
the
Export,
Temp
and
Index
folders
you
created
for
the
new
case.
Click Finish.
Case
Management
Next,
select
File
Save
or
click
on
the
Save
icon
on
the
toolbar.
Navigate
to
the
root
of
the
Barrow
folder
in
your
Cases
folder
and
enter
a
name
for
the
case
le
(e.g.
CBarrow.case).
Click
on
Save
to
save
the
new
case
le.
Saving a case
Academic Program
PRACTICAL 1.2
10
11
12
13
14
Academic Program
PRACTICAL 1.3
17
18
Options
19
Auto
Save
Use
Recycle
bin
for
cases
Show
True
/
Show
False
Enable
Picture
Viewer
Enable
ART
and
PNG
image
display
Invalid
Picture
Timeout
Enable
Pictures
in
Doc
view
Date/Time
formats
Flag
Lost
Files
Debug
Global Options
20
Global Options
21
EnScript
These
are
small
programs
that
can
automate
the
examinaon
process.
This
opon
species
the
locaon
of
the
EnScript
libraries
folder
which
contains
programming
modules
used
by
mulple
EnScript
programs.
EnScripts Options
22
Storage
Paths
This
opon
allows
an
examiner
to
congure
the
locaon
of
.INI
les
used
by
EnCase
to
establish
global
sengs.
By
default
these
les
are
stored
in
C:\Program Files\EnCase6\Config.
23
Table Pane
Tree Pane
View Pane
Filter Pane
24
Right-clicking
on
an
object
in
the
Tree
Pane
will
bring
up
a
context
menu
with
many
selecons
including
the
choice
to
expand
or
contract
everything
from
the
selected
posion.
Everything
in
the
case
will
be
aected
by
right-clicking
on
the
Entries
folder.
Folder Structure
25
Highlighng
a
folder
The
Set
Include
Opon
The
Blue-check
Highlighting a Folder
26
Highlighng
a
folder
The
Set
Include
Opon
The
Blue-check
27
Highlighng
a
folder
The
Set
Include
Opon
The
Blue-check
28
29
30
Gallery
Displays
images
in
a
thumbnail
view.
These
images
are
displayed
(by
default)
based
on
their
extension.
33
Timeline
View
Shows
paerns
of
dierent
types
of
dates
and
mes.
You
can
zoom
in
(Higher
Resoluon)
to
a
second-by-
second
meline
and
zoom
out
(Lower
Resoluon)
to
a
year-by-year
meline.
34
Disk
View
Allows
viewing
of
les
and
folders
in
terms
of
where
the
data
appeared
on
the
media.
Placement
of
clusters
and/or
sectors
and
fragmentaon
of
les
may
be
observed.
35
36
37
38
39
40
Bibliography
42