From the simplest requirements to the most complex. EnCase Forensic gives investigators the ability to image a drive and preserve it in a forensic manner using the EnCase evidence file format (LEF or E01), a digital evidence container vetted by courts worldwide.
EnCase Forensic also contains a full suite of analysis, bookmarking and reporting features. Guidance Software and third party vendors provide support for expanded capabilities to ensure that forensic examiners have the most comprehensive set of utilities.
EnScripts and customizable filters allow examiners of all experience levels can quickly parse out relevant data for further review with pre-built EnScripts or by developing their own EnScript tools.
EnCase Forensic also offers powerful hidden volume detection and volume rebuilding capabilities, allowing investigators to review evidence that would have been irretrievable with other computer forensics applications.