EnCase® Virtual File System
All EnCase® modules and any other modules released during the three-year subscription period. Current modules include
Mounts evidence at the cases, case, device, volume, or folder level as a read-only network share. (It appears as a network share to the local operating system but the share is not available to other users over the network).
VFS provides an easy platform for information or evidence review in a read-only state outside of the EnCase® environment.
Provides an intuitive platform for evidence to be reviewed by case agents/investigators, opposition experts, prosecutors and defense counsel.
Files contain the same file system artifacts as contained in EnCase®, including all allocated files, deleted files, internal system files as well as alternate data streams and unallocated space.
Once mounted, the read-only media is available to any native application, including Windows Explorer and third-party Windows applications or computer forensic tools such as file carving utilities, virus checkers, spyware detectors, trojan detectors, steganography detectors, word indexers, undelete software and encryption detection software.
Review evidence with non-EnCase® users.
File Systems supported: DOS (FAT 12/16/32, NTFS), Linux (EXT2, EXT3, Reiser), UNIX (Solaris UFS), Macintosh (HFS, HFS+), BSD (FFS), CD/DVD (Joliet, ISO 9660, UDF, DVD) and Palm (Palm OS).
Easily mounts Windows RAIDS, Dynamics Disks rebuilt by EnCase® and drives compressed or encrypted by NTFS.