EF FS EnCase Forensic Imager Webready
EF FS EnCase Forensic Imager Webready
EF FS EnCase Forensic Imager Webready
Quickly Acquire Evidence in a Forensically Sound Manner with EnCase Forensic Imager
When time is short and you need to acquire entire volumes or selected individual folders or files,
EnCase Forensic Imager is your tool of choice. Based on trusted, industry-standard EnCase
Forensic acquisition technology, EnCase Forensic Imager:
EnCase Forensic Imager may be used to acquire entire volumes (Ex01/E01) or selected
individual folders or files (Lx01/L01). In addition, EnCase Forensic Imager uses the same
trusted acquisition engine available in EnCase Forensic itself and has the same familiar interface
as EnCase Forensic Version 7. In addition, encryption allows the evidence to be packaged and
shipped without concern that spoilage may occur.
EnCase Forensic imager can acquire local drives and is perfect for triaging a computer or hard
drive to view folder structures and metadata. Finally, Imager can be deployed on a USB stick to
perform an acquisition of a live device.
Technical Notes
No install is required; files associated with the program are loaded into the
User Data directory
EnCase Forensic Imager runs on Microsoft Windows Machines
Users can acquire local drives, but not user-mapped network drives. Acquisition of usermapped network drives is recommended from the source server itself
www.encase.com