EnCase® Virtual File System

 

 

  • All EnCase® modules and any other modules released during the three-year subscription period.  Current modules include
  • Mounts evidence at the cases, case, device, volume, or folder level as a read-only network share. (It appears as a network share to the local operating system but the share is not available to other users over the network).
  • VFS provides an easy platform for information or evidence review in a read-only state outside of the EnCase® environment.
  • Provides an intuitive platform for evidence to be reviewed by case agents/investigators, opposition experts, prosecutors and defense counsel.
  • Files contain the same file system artifacts as contained in EnCase®, including all allocated files, deleted files, internal system files as well as alternate data streams and unallocated space.
  • Once mounted, the read-only media is available to any native application, including Windows Explorer and third-party Windows applications or computer forensic tools such as file carving utilities, virus checkers, spyware detectors, trojan detectors, steganography detectors, word indexers, undelete software and encryption detection software.
  • Review evidence with non-EnCase® users.
  • File Systems supported: DOS (FAT 12/16/32, NTFS), Linux (EXT2, EXT3, Reiser), UNIX (Solaris UFS), Macintosh (HFS, HFS+), BSD (FFS), CD/DVD (Joliet, ISO 9660, UDF, DVD) and Palm (Palm OS).
  • Easily mounts Windows RAIDS, Dynamics Disks rebuilt by EnCase® and drives compressed or encrypted by NTFS.