> For the complete documentation index, see [llms.txt](https://wongkenny240.gitbook.io/computerforensics/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wongkenny240.gitbook.io/computerforensics/encase/advanced-encase.md).

# Advanced EnCase

## Recover Partition

## Mounting Evidence as VFS

Virtual File System (VFS) mounts a drive, volume or folder as read-only offline network share.

![](https://3899724814-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LbSIGOSblVtuEjzcmhL%2F-MFGJ4z2-H_Azcg9D4cR%2F-MFGJ6M0B4d88BQ4U8hr%2Fimage.png?alt=media\&token=139fcb11-0760-43a6-970f-82a7c0f1121e)

1. Device > Share > Mount as Network Share
2. Input Server Info, client info

*Note: To stop the VFS service, double click “Virtual File System” in lower-right corner*

![](https://3899724814-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LbSIGOSblVtuEjzcmhL%2F-MFGJ8MxM0pPNfHb9ycb%2F-MFGJaWu_8IfjveJXjqX%2Fimage.png?alt=media\&token=69c7b80b-e191-4fbe-a769-b8579c280ef0)

## Mount evidence as PDE

Mounting evidence by Physical Disk Emulation is like mounting the disk as an actual physical disk attached to the examiner machine.&#x20;

This enables analysis of the evidence using other forensic tools, or use it to boot into a virtual machine. But this limits the supported file systems for casual browsing to those supported by windows (i.e. FAT & NTFS)

![](https://3899724814-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LbSIGOSblVtuEjzcmhL%2F-MFGJe5TSwASnkPZvyDa%2F-MFGKB7u5MfSsgenFQi6%2Fimage.png?alt=media\&token=aafab944-de7a-4faf-8367-9a1f560cbef5)

1. Device > Share > Mount as Emulated Disk
2. Selecting “Disable Cache” enables write-emulation, and changes are sent to cache folder (similar to mounting by FTK imager and Arsenal Image Mounter's "Write temporary disk device")

![](https://3899724814-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LbSIGOSblVtuEjzcmhL%2F-MFGJe5TSwASnkPZvyDa%2F-MFGKfyMaobw6qEpVew1%2Fimage.png?alt=media\&token=12070704-c24a-4259-a336-8fd3481c699d)

## Booting it into a VM
