[www.ed2k.online]下載基地為您提供軟件、遊戲、圖書、教育等各種資源的ED2K電驢共享下載和MAGNET磁力鏈接下載。
設為首頁
加入收藏
首頁 圖書資源 軟件資源 游戲資源 教育資源 其他資源
 電驢下載基地 >> 软件资源 >> 行業軟件 >> 《電子數據取證分析軟件》(EnCase®)V6.01[光盤鏡像]
《電子數據取證分析軟件》(EnCase®)V6.01[光盤鏡像]
下載分級 软件资源
資源類別 行業軟件
發布時間 2017/7/11
大       小 -
《電子數據取證分析軟件》(EnCase®)V6.01[光盤鏡像] 簡介: 中文名 : 電子數據取證分析軟件 英文名 : EnCase® 資源格式 : 光盤鏡像 版本 : V6.01 發行時間 : 2010年 制作發行 : Guidance Software, Inc. 語言 : 英文 簡介 : EnCase V6電子數據取證分析軟件 EnCase Forensic 是一套旗艦級電腦犯罪鑒識軟體,目前為全球多數法庭將EnCase作為電腦犯罪偵查
電驢資源下載/磁力鏈接資源下載:
全選
"《電子數據取證分析軟件》(EnCase®)V6.01[光盤鏡像]"介紹
中文名: 電子數據取證分析軟件
英文名: EnCase®
資源格式: 光盤鏡像
版本: V6.01
發行時間: 2010年
制作發行: Guidance Software, Inc.
語言: 英文
簡介:

EnCase V6電子數據取證分析軟件
EnCase Forensic 是一套旗艦級電腦犯罪鑒識軟體,目前為全球多數法庭將EnCase作為電腦犯罪偵查之認證工具,已有超過百萬件之公開使用案例。該軟體被設計為以鑒識角度來取得電磁資料,並有強大的比對與分析工具可供使用,不僅可復原被抹除的資料檔案,還能進行各種資料的分析作業,幫助檢調人員取得犯罪證據。
EnCase軟件被司法、政府、軍隊、公司監查等部門廣泛采用,查找並管理計算機中的數據。通過EnCase,調查員可以輕松管理計算機中的大量證據,包括已經刪除的文件、閒散文件以及未分配空間中的數據。
產品特點:
使用方便,可以獲取各種系統的鏡像文件
自動生成詳細報告,以RTF或HTML形式導出
方便的圖片查看器,支持ATR,BMP,GIF,JPG,PNG和TIFF等多種格式
擴展時間標簽,可以查看文件的創建時間,最近訪問或修改時間等活動
支持各種文件系統,如FAT16,FAT32,NTFS,Macintosh HFS,HSF+,Sun Solaris UFS,Linux EXT23,Reiser,BSD FFS,Palm,TiVo Series One Two,AIX JFS,CDFS,Joliet,DVD,UDF和ISO 9660等
支持RAID磁盤陣列
支持多種郵件格式,如Outlook,Outlook Express,Yahoo,Hotmail,Netscape Mail和MBOX,還支持AOL 6.0,7.0,8.0,9.0和PFCs等
支持多種浏覽器格式,如IE,Mozilla Firefox,Opera和Apple Safari等

計算機取證分析軟件的核心技術之一在於它對各種文件系統的支持。只要取證軟件支持文件系統的解析,那麼就無需熟悉操作系統運行環境,即可讀取、分析硬盤中所存儲的文件夾/文件列表,甚至是刪除文件。
EnCase作為老牌的計算機取證分析軟件,它在文件系統支持方面相當全面,可以用卓越來形容。目前也是全球取證分析軟件中對文件系統支持最為全面的。
EnCase V6支持的文件系統: Windows: FAT12/FAT16/FAT32/NTFS/exFAT
Macintosh: HFS/HFS+
Linux: EXT2/EXT3/Reiser/LVM2
FreeBSD: FFS/UFS2
IBM AIX: JFS/JFS2/LVM8
Novell : ZFS/NWFSNSS/
Sun Solaris: SUN ZFS/ SUN UFS
HP-UX: vxfs
TiVo: TiVo 1/TiVo2
光盤系統:ISO 9660/Joliet/UDF
其它:Palm (PDA)
EnCase目前還不支持Ext4文件系統。

EnCase® Enterprise has changed the landscape of enterprise and computer investigations by providing complete network visibility, immediate response and comprehensive, forensic-level analysis of servers and workstations anywhere on a network. EnCase® Enterprise is a scalable platform that integrates seamlessly with your existing systems to create an enterprise investigative infrastructure. This cutting-edge solution can be tailored to meet your unique needs, including the automation of time-consuming investigative processes, auditing endpoints for sensitive information and eDiscovery.
Securely investigate/analyze many machines simultaneously over the LAN/WAN at the disk and memory level.
Acquire data in a forensically sound manner, using software that has an unparalleled record in courts worldwide.
Limit incident impact and eliminate system downtime with immediate response capabilities.
Investigate and analyze multiple platforms — Windows, Linux, AIX, OS X, Solaris and more — using a single tool.
Efficiently collect only potentially relevant data upon EnCase eDiscovery requests.
Proactively audit large groups of machines for sensitive or classified information, as well as unauthorized processes and network connections.
Identify fraud, security events and employee integrity issues wherever they are taking place — then investigate/remediate with immediacy and without alerting targets.
Identify and remediate zero-day events, injected dlls, rootkits and hidden/rogue processes.
Case Indexer
EnCase® V6 introduces our new patent-pending, powerful indexing engine which indexes text extracted from the Stellent™ Outside In Technology. You can now build a complete index of words from multiple languages based on your evidence file and then create fast and easy queries using EnCase® Conditions and Filters. These indices can be chained together to find possible keywords in common with other investigations. The Unicode-supported index is built from the contents of personal documents, deleted files, file system artifacts, file slack, swap files, unallocated space, emails and web pages.
64-bit Support
EnCase® Forensic now comes in 32 bit and 64 bit. Common investigations are now involving hundreds of gigabytes to tens of terabytes of static data requiring analysis. The amount of this data easily exceeds the memory addresses in 32-bit software. In today's 32-bit desktop systems, there can be up to 4GB of RAM (provided the motherboard can handle that much RAM) which is split between the applications and the operating system. Users will note a performance increase, because a 64-bit CPU can handle more memory and larger files. One of the most attractive features of 64-bit processors is the amount of memory the system can support. 64-bit architecture will allow systems to address up to 1 terabyte (1000GB) of memory. The new 64-bit version of EnCase® Forensic v6 delivers improved multi-threading and a more efficient use of all available memory.
Native File Viewer
EnCase® Examiner v6 has incorporated the Stellent™ Outside In file-viewing technology and now displays over 400 file formats natively in the Doc panel.
Enhanced Email Support to Natively Parse
Guidance Software has added the following NEW email formats to EnCase® v6 and now natively presents their contents without their application:
MS Exchange 2000/2003 EDBs
Lotus Notes NSFs versions 5, 6, 6.5 and 7
Hard Disk Caching for Email Parsing
In v6, EnCase® Forensic now uses disk caching to quickly open large and complex compound files, such as Lotus Notes NSFs and Microsoft EDBs and PSTs.
Additional File System Support
Guidance Software has added the following NEW file systems to EnCase® v6 and now presents the folder/file structures:
FreeBSD’s Fast File System 2 (FFS2)
FreeBSD’s UFS2
Novell NWFS
Novell NSS
Although the NWFS file system has been used by Novell since NetWare version 2x, EnCase only currently supports NetWare versions 5.1, 6.0 and 6.5 with either the NWFS or NSS file system.
Support for Apple® DMG Files
The file extension, dmg, is for Macintosh® OS X Disk Copy disk image files. Treated like a real disk, these files can now be added to EnCase® Forensic, displaying the internal file/folder structure
Support for Apple / Unix Files Compressed with PAX
Files compressed in a Macintosh / Unix environment using the PAX (Portable Archive Exchange) command can be saved in either tar or cpio format. EnCase® Forensic v6 now includes support for the parsing of BOTH cpio and tar PAX compressed files.
Support for Gzip Compressed Archive Files
EnCase® Forensic v6 adds Gzip (zlib) support for regular (non-compressed) files. EnCase® software does NOT yet support bzip or adc formats.
Alternate Path
How may times have you set up your equipment to acquire a drive image, only to have run out of drive space? EnCase® Forensic v6 now allows you to set an alternate destination volume for evidence files at the start of the media acquisition.
Display of Hard Disk Serial Number
Are you tired of removing the suspect hard drive to document the serial number from the label? Hard disk acquisitions with EnCase® Forensic now read and document the true serial number and the volume serial number for the media. NOTE: Acquisitions made with versions 1–5 will NOT display this information.

No NFO available Forensic Toolkit as used in a Police Station near you


EnCase® Enterprise System Requirements
Guidance Software recommends the following minimum hardware requirements for EnCase®
Enterprise Edition:
SAFE
• Windows 2000 or 2003 Server
• 1.5+ GHz Pentium IV Processor (2.4 GHz Pentium IV Processor or better recommended)
• 512 MB of RAM (1 GB or more recommended)
• 1 dedicated USB Port / Gigabit Network Card
• Not recommended for Evidence storage
EXAMINER
• Windows 2000, XP, Vista or 2003 Server
• 2.0 GHz Pentium IV Processor (3.0 GHz Pentium IV Processor or better recommended)
• 1 GB of RAM (2 GB or more recommended)
• 1 dedicated USB Port (when not using NAS) / Gigabit Network Card
• Ample data storage for evidence file acquisitions recommended (500GB or more)
SERVLET
• Available for Windows, NT, 2000, XP, Vista and 2003 Server; Linux kernel 2.4 and above, designed for Red Hat, SuSE & Mandrake; Sun Solaris 8 & 9, both 32- and 64-bit processors, AIX 4.3, 5.1,5.2 & 5.3 and MAC OSX version 10.2,10.3, & 10.4.

下載鏈接來自STF
未經過安裝測試與安全檢測,使用者後果自負與本論壇無關
軟體版權歸原作者及其公司所有,如果你喜歡,請購買正版


相關資源:

免責聲明:本網站內容收集於互聯網,本站不承擔任何由於內容的合法性及健康性所引起的爭議和法律責任。如果侵犯了你的權益,請通知我們,我們會及時刪除相關內容,謝謝合作! 聯系信箱:[email protected]

Copyright © 電驢下載基地 All Rights Reserved