Basic EnCase
Creating a Case
Templates: has an extension of .CaseTemplate and is stored in the Users\Documents\EnCase\Templates folder.
Case information items with default values
Bookmark folders and notes
Tag names
Report template
User-defined report styles
Base Case Folder: By default, your cases will be stored in your Documents or My Documents folder.
Primary Evidence Cache : When EnCase loads an evidence item for viewing, it parses and stores metadata associated with that evidence item. Each acquired evidence item is assigned a GUID, and a folder by that GUID name will contain the cached data associated with that evidence item.
Secondary Evidence Cache: This location is for previously created caches
Case Info: several fields into which you can or should enter data pertaining to the case. The fields will vary according to the template you select in Templates
EnCase Folder Structure
EnCase creates subfolders called Email, Export, Tags, and Temp.
User need to manually created Evidence and EvidenceCache.
EnCase View
Placeholder
Verify Evidence
Evidence tab > drop down menu > Verify File Integrity > File Integrity/ MD5/SHA-1 / CRC Errors
Note: Add Evidence will automatically verify the new evidence file added to the case, also reopening the case will verify the evidence files which is not verified yet.
Timeline view
Tree Pane > Set Included > Timeline view > Higher Resolution or Lower Resolution
Date Types > select which timestamps to be viewed
Sort
First sort (either one of the following):
Open sort menu from Table toolbar
Double click the header of the column you want to sort
Second sort:
Hold down the Shirt key > double click the column header
Sort in opposite direction:
CTRL + double click column header
CTRL + SHIFT + double click the column header
Remove Sort:
Remove sort in the Sort menu
Double click
Gallery view
See images -> Set Include Folders button in the Tree pane, you can direct the content of the Table pane
EnCase displays images based on the file extension. After the file signature analysis has been completed, the files will display based on their file header information.
Disk view
Evidence tab -> Place the cursor on device -> Device -> Disk View
By default, you see a series of colored square blocks, each representing one sector. If you would prefer that each block represent a cluster, simply click the check box next to View Clusters on the toolbar for this view.
Blue blocks are allocated sectors or clusters.
The gray blocks with the raised bump in the center are unallocated sectors or clusters.
Go to a sector by typing in the sector number -> Go To feature from its menu on the Disk View toolbar
File Types view
Add File Type View > File Types > New
Add a File Viewer Open With > File Viewers > New File Viewer
Evidence Processor
File Signature Analysis
Create a new file signatures
Running File Signature Analysis against Selected Files
Blue check the specific files you want to run signature analysis on.
Click Entries. In the dropdown menu, click Hash\Sig Selected. The Hash\Sig Selected dialog displays.
Select Verify file signatures to run signature analysis.
Click OK and refresh the device after running
File Signature Analysis
Search for different types of results with filter
Find Entries by Signature
The results will be in Result tab
Hash Analysis
Creating hash libraries and hash sets
Before you can create any hash sets from within EnCase, you must first create a hash library container, which is a folder containing a series of file-based, database-like structures into which EnCase will store hash sets.
Tools -> Manage Hash Libraries
Manage hash libraries -> new hash library
Importing legacy hash sets into EnCase
Adding hash values to the hash sets and library
Query the hash libraries for a MD5 hash
Manage Hash Library -> Query
Add to hash library -> Right Click New Hash Set
Using hash values to identify/exclude files
Entries -> Hash\Sig Selected
Find Entries by Hash Category -> Result tab
Hash Analysis Summary
Creating a Hash Library
Tools > Manage Hash Library
New button
Browse for a folder -> click OK
Import hash sets from another library
Tools > Manage Hash Library
Click Import from the toolbar
Creating a Hash Set
Tools > Manage Hash Library
click New Hash Set. The Create Hash Set dialog appears
Adding Hash Values to a Hash Set
Hash the item by right click item Entries -> Hash\Sig Selected
Right click Entries -> Add to hash library
Choose the hash library to add to
Select one existing hash sets or create new hash set by right clicking
Select Fields
Adding Hash Values to a Hash Set from Results
Last updated