Product Information

EnCase Forensic v7

starstarstarstar¼

by Brendan Carroll May 20, 2013
Vendor:

Guidance Software

Product:

EnCase Forensic v7

Website:

http://www.guidancesoftware.com

Price

£2,282, includes one-year SMS

RATING BREAKDOWN

  • Features:
    starstarstarstar
  • Ease of Use:
    starstarstarstar
  • Performance:
    starstarstarstar½
  • Documentation:
    starstarstarstar
  • Support:
    starstarstarstar½
  • Value for Money:
    starstarstarstar½
  • Overall Rating:
    starstarstarstar¼

QUICK READ

  • Strengths: A solid computer/media/mobile device forensic tool with a history of experience
  • Weaknesses: Can be dicey to set up in a network environment with multiple other products’ CodeMeter dongles running on a networked licence server
  • Verdict: The usual reliable, solid offering we expect from this vendor

Encase Forensic v7 is a tool for computer investigation that both searches a computer system for information, as well as aids in the process of developing this information into a complete report. This software can decrypt high-level forms of encryption, create an image of the physical drive, and then generate reports on the evidence.

After some initial challenges - the package we received did not include all necessary information - we were able to contact Guidance Software and receive the files necessary to install the software. The customer service was helpful in getting us through the install process after we encountered problems getting the software fully functional. We must say it took a lot of time to finally get all of the necessary information for the installation process.

We determined that the software had trouble running on a network of computers using multiple CodeMeter dongles. The EnCase software would run and display an error message claiming it did not have all proper licence certificates. Forensic v7 uses a secure key from the CodeMeter dongle so when operating on a network with multiple dongles, it had trouble identifying which secure keys related to the product. To get it to run on our network, we had to disable all our other tools that used a similar secure key. Otherwise, it would try to identify these keys as its own and fail to run. This means that while the software ran very well once it had its licence identified, it might prove to be a nuisance on systems with many tools running that use CodeMeter dongles. Disabling the other secure keys would be both time-consuming and prevent one from using multiple tools in tandem. Therefore, our installation was time-consuming and we had to jump through hoops to get the software to operate on our network, though it did eventually work - and work very well, indeed.

EnCase Forensic v7 claims to be a comprehensive, industry-standard computer investigation solution - and it does not disappoint. The user interface is a clean, simple and comfortable platform from which to work. The flexibility and versatility of the interface is one of the product's greatest strengths, as it creates a more valuable experience for the user. The features also help to make it an attractive option. It provides the capability to analyse Linux, Unix and Mac systems, as well as major phone and tablet operating systems, such as Android, Apple iOS and more. The evidence processor is customisable and efficient. 

The interface of the program is easy to use and user friendly. The software is well organised. The search results becoming available as they load is also a useful feature, as is the ability to create a report of the evidence and findings. While the software encountered minor difficulties when beginning the installation process, the support staff were so helpful and were able to help us develop a workaround for our particular network.

EnCase is, arguably, the grandparent of computer forensic tools and this legacy of experience shows in each new release. This one is no exception. Version 7 has a good combination of ease of use for the novice and comprehensive capability for the power user.

Related Group Test

SC Webcasts UK

Sign up to our newsletters

FOLLOW US