Hello.. Hi.. I just completed my computer forensics degree .... i am trying to upgrade my knowledge in digital forensics. could anyone please advice me whether FTK or Encase.. among these two which is the best course for career... could anyone please let me know...
Nice tool, but basic. There are free programs, live CDs out there that are much better - and free. Real security and real forensic work is done with Linux, not Windows.
Nice tool, but basic. There are free programs, live CDs out there that are much better - and free. Real security and real forensic work is done with Linux, not Windows.
@skingbinsane If you believe that is the only tool they use, you are sadly misinformed. Windows lacks certain tools and abilities found in other operating systems and tools under them.
@RoadieRon Where did I say it was the "only tool used?" I'm not pulling this info out of thin air, I have talked with a director at a RCFL and was given a brief on the lab at the different platforms used and the main software used... They also use FTK by the way... They have pretty much everything to deal with a hardware and software configuration including every imaginable legacy system you can think of.
@skingbinsane very true. They do have many tools. I work in the security field with the us military, law enforcement and also wit hthose often-3-letter-agencies of the us government. autopsy, photorec, C.A.I.N.E, D.E.F.T, EnCase,FTK, scalpel, and many other tools are used. Getting data is important, but Computer Forensics is also largely *HOW* and *WHY* you got the data, lest it not be admissable in a court of law.
EnCase and in fact no forensic tools I've seen recently cannot counter the anti-forensic tools eg linux tools, encryption and wiping tools (if done correctly.)
These forensic tools are okay against the user that knows nothing but are useless against the savvy user or even the ordinary user that knows how to google.
Hey you cant crack this software...I am an Forensic computing student and u cant crack the new version...My first project was to crack EnCase..I drop that project due to its difficulty...U need the Dongle...costs up to 10000$
@cssbrainDOTcom I disagree sir. I hide all my CP on encrypted virtual machines inside of encrypted file containers, with an AES-Serpant-Twofish algorithm, and keyfiles stored off site.
Actually, it is possible to crack the new encase (v6) - and without the dongle too! Infact, getting past the dongle protection is the easy bit, it's the FIPS integrity crap thats the pain in the bum.
Regardless, a commercial copy dosnt cost $10,000, its around $2000.
you have to have a cable to make the software work which costs like thousands of dollars... thats how they get you. You can have to program through a crack but in order to actually use it u need the cable...
believe it.... i took a cybercrime course and the head director at FDLE told us.... he would know he had the program and the master cable that you need....
I've been unsuccessful retrieving any files from a USB thumbdrive encrypted with AES, is there any way around this? I can't even see the partition, but it is mountable with truecrypt if you have the password.
I tried using EnCase after using Terminus 6 and I was not successful in recovering anything. Just some weird file names like jfInnfsnIOW.o0f that were like 200 megs and with lots of weird characters.
it won't find anything overwritten even once. But are you sure windows didn't make a separate copy of the file? When rar files vanish on their own from your temp directory where do they go? For run of the mill file recovery you would not want to use encase. Encase is a pain in the ass it's just the industry standard
Whole disk encryption renders all forensics useless. And while it sounds intimidating it's not that difficult.
Interesting.. I have a computer I haven't used since I was about 14, and I'm 19 now. So I could maybe see my chat logs from that long ago? + Also could I just ask you that, aside from reformat the computer, does a disk defrag go over all the deleted files you've deleted and actually delete them so they wouldn't show up in any software of this type?
Nope, a defrag will usually jumble things around pretty good is the drive is heavily fragmented. To really wipe things you need something like "Eraser", for wiping free space, or "Dban" for wiping the whole disk.
@threesandals you ARE A JACKASS. The disk defrag will copy all parts of the file somewhere on the hard disk and then write it back to the back of the file before it. It jumbles nothing. If after all the files written to the hard disk you have space that hasnt been used or rewritten. That is the stuff encase will find. If you lucky enough that the evidence was in untouched space than you got it but if not the perp gets off.
hi gr8 vid, thanks sir :-) sorry for asking but my brov is a e-forensics expert, i was thinking is there any books or information i could get, i like to learn the subject, but to be honest have no way to increase what little knowledge, some help for a grasshopper plz, thanks
Good but real bad guys use Truecrypt (full disk encryption) disklabs has no answer to Truecrypt.
Not only that they use Dban to clean data from a hard drive which if used correctly renders all the most advanced computer forensic microscopes obsolete
Well, it didn't cost *me* anything because I'm resourceful >:->. But I believe that Guidance Software would probably not have any problem sending out a demo copy to a student. I'm not sure if they do demos or not, but it would probably be worth a try.
Hi! thanks for the tutorial... I was wondering is there any books or videos out there which has more tutorial for new users? or any compant that offer free training? I was looking at the training course in software guidance that they offer and its costs 1000+ for phase1 and another 1000+ for phase2... I cant afford it at the moment because i'm at uni studying Forensic coputing.... and i loads for it as it is....
Well, you can always download the EnCe Study Guide PDF (or buy the book I suppose). It is the study guide for people working toward Guidance Software's EnCe Encase certification...
Yeah, YouTube scales it down quite a bit which is the reason for the "blurryness". The unscaled version that I posted on Freenet looks pretty good. I did use Camtasia Studio BTW.
hey i guttman 35 passed my entire free disc space can shit still be recovered using this program??????????????????
GarrlicSauce 2 months ago
Apologies for the dumb question, but will this software uncover an originating IP for the data from a USB?
MyTeffy1 3 months ago
Hello.. Hi.. I just completed my computer forensics degree .... i am trying to upgrade my knowledge in digital forensics. could anyone please advice me whether FTK or Encase.. among these two which is the best course for career... could anyone please let me know...
jesforchrist 4 months ago
from where did you download and what is the license key!!
please help!!
adityaiswest 1 year ago
@adityaiswest RAPIDSHARE ;)
DSetekh 1 year ago
This has been flagged as spam show
Nice tool, but basic. There are free programs, live CDs out there that are much better - and free. Real security and real forensic work is done with Linux, not Windows.
RoadieRon 1 year ago
Nice tool, but basic. There are free programs, live CDs out there that are much better - and free. Real security and real forensic work is done with Linux, not Windows.
RoadieRon 1 year ago
@RoadieRon lol... EnCase is used in FBI Forensics Labs... Most work is done on Wintel boxes... You're grossly misinformed.
BTW, the version in this video is pretty dated so theres that too.
skingbinsane 1 year ago
@skingbinsane If you believe that is the only tool they use, you are sadly misinformed. Windows lacks certain tools and abilities found in other operating systems and tools under them.
RoadieRon 1 year ago
@RoadieRon Where did I say it was the "only tool used?" I'm not pulling this info out of thin air, I have talked with a director at a RCFL and was given a brief on the lab at the different platforms used and the main software used... They also use FTK by the way... They have pretty much everything to deal with a hardware and software configuration including every imaginable legacy system you can think of.
skingbinsane 1 year ago
@skingbinsane very true. They do have many tools. I work in the security field with the us military, law enforcement and also wit hthose often-3-letter-agencies of the us government. autopsy, photorec, C.A.I.N.E, D.E.F.T, EnCase,FTK, scalpel, and many other tools are used. Getting data is important, but Computer Forensics is also largely *HOW* and *WHY* you got the data, lest it not be admissable in a court of law.
RoadieRon 1 year ago
@RoadieRon bullcrap.
quelorepario 9 months ago
@quelorepario whatever.....
RoadieRon 9 months ago
When I do this for the local drive it says:
"none of the selected devices are available"
Can anyone help with this?
viewervideo011242234 2 years ago
@viewervideo011242234 must run as Administrator
gam3kid 1 year ago
EnCase and in fact no forensic tools I've seen recently cannot counter the anti-forensic tools eg linux tools, encryption and wiping tools (if done correctly.)
These forensic tools are okay against the user that knows nothing but are useless against the savvy user or even the ordinary user that knows how to google.
rhizophagus 2 years ago
Whats the name of that program?
FLStudio4512 2 years ago
@rhizophagus well said
mourkos 1 year ago
if you have this software could you bring back msn conversations that you never saved to your computer?
vaantjuh90 2 years ago
Comment removed
brandon385 2 years ago
Comment removed
brandon385 2 years ago
Completely Awesome! Encase rocks!
deeblackat 2 years ago
Hey you cant crack this software...I am an Forensic computing student and u cant crack the new version...My first project was to crack EnCase..I drop that project due to its difficulty...U need the Dongle...costs up to 10000$
ma1n1m 2 years ago
Nothing can't be cracked mate, just a question of time and will...
cssbrainDOTcom 2 years ago 7
@cssbrainDOTcom I disagree sir. I hide all my CP on encrypted virtual machines inside of encrypted file containers, with an AES-Serpant-Twofish algorithm, and keyfiles stored off site.
I Joke I joke!!!
Uuxaul 7 months ago
Actually, it is possible to crack the new encase (v6) - and without the dongle too! Infact, getting past the dongle protection is the easy bit, it's the FIPS integrity crap thats the pain in the bum.
Regardless, a commercial copy dosnt cost $10,000, its around $2000.
I dont think you tried hard enough !
mindwarexxx 2 years ago
I wonder if anybody could send me a EnCase4.2 cracked, I have download one,however it seems have some problem. Thank you very much!!
dzf203 2 years ago
you have to have a cable to make the software work which costs like thousands of dollars... thats how they get you. You can have to program through a crack but in order to actually use it u need the cable...
theurbanbear 2 years ago
a cable costing 1000 dollars? i dont believe you
cofusion9 2 years ago
believe it.... i took a cybercrime course and the head director at FDLE told us.... he would know he had the program and the master cable that you need....
theurbanbear 2 years ago
Its a USB dongle and not a cable. It does cost a lot, but it is a seriously powerfull tool.
ALUMINUM20 2 years ago
I've been unsuccessful retrieving any files from a USB thumbdrive encrypted with AES, is there any way around this? I can't even see the partition, but it is mountable with truecrypt if you have the password.
PILMAN 2 years ago
Drive not ready error blabla *foams at mouth.. slits wrists*
plowy 3 years ago
this is very interesting im learing on how to use this software (school stuff)
MrCARC 3 years ago
I tried using EnCase after using Terminus 6 and I was not successful in recovering anything. Just some weird file names like jfInnfsnIOW.o0f that were like 200 megs and with lots of weird characters.
PILMAN 3 years ago
where can you get a copy of encase
ducksoup2007 3 years ago
This has been flagged as spam show
does anhyone have msn!!! msg me jane24belle
ewaars 3 years ago
This has been flagged as spam show
my pusssy is wet
bheibykoh08 3 years ago
This has been flagged as spam show
my cock is hard
tehbigtoaster 3 years ago
You know there is such a thing as Anti computer forensics...You can beat $3,000 soft wear.
chibi2666 3 years ago
The price of the software doesn't automatically make it better.
darkwolf228 2 years ago
Will the program find anything when i have overwritten my free disk space 35 times (guttman)?
generaldeejee 3 years ago
it won't find anything overwritten even once. But are you sure windows didn't make a separate copy of the file? When rar files vanish on their own from your temp directory where do they go? For run of the mill file recovery you would not want to use encase. Encase is a pain in the ass it's just the industry standard
Whole disk encryption renders all forensics useless. And while it sounds intimidating it's not that difficult.
andocrates 3 years ago
Interesting.. I have a computer I haven't used since I was about 14, and I'm 19 now. So I could maybe see my chat logs from that long ago? + Also could I just ask you that, aside from reformat the computer, does a disk defrag go over all the deleted files you've deleted and actually delete them so they wouldn't show up in any software of this type?
SAMLAD2k6 3 years ago
Nope, a defrag will usually jumble things around pretty good is the drive is heavily fragmented. To really wipe things you need something like "Eraser", for wiping free space, or "Dban" for wiping the whole disk.
threesandals 3 years ago
@threesandals you ARE A JACKASS. The disk defrag will copy all parts of the file somewhere on the hard disk and then write it back to the back of the file before it. It jumbles nothing. If after all the files written to the hard disk you have space that hasnt been used or rewritten. That is the stuff encase will find. If you lucky enough that the evidence was in untouched space than you got it but if not the perp gets off.
roboptions 7 months ago
p.s my brov is a git and woun't help his lil brov, also i think he is too bigheaded,
smartchip 4 years ago
hi gr8 vid, thanks sir :-) sorry for asking but my brov is a e-forensics expert, i was thinking is there any books or information i could get, i like to learn the subject, but to be honest have no way to increase what little knowledge, some help for a grasshopper plz, thanks
smartchip 4 years ago
Good but real bad guys use Truecrypt (full disk encryption) disklabs has no answer to Truecrypt.
Not only that they use Dban to clean data from a hard drive which if used correctly renders all the most advanced computer forensic microscopes obsolete
john477h 4 years ago
I'm currently studying computer forensics myself. How much did the program alone cost you?
0megamanX 4 years ago
Well, it didn't cost *me* anything because I'm resourceful >:->. But I believe that Guidance Software would probably not have any problem sending out a demo copy to a student. I'm not sure if they do demos or not, but it would probably be worth a try.
threesandals 4 years ago
Hi! thanks for the tutorial... I was wondering is there any books or videos out there which has more tutorial for new users? or any compant that offer free training? I was looking at the training course in software guidance that they offer and its costs 1000+ for phase1 and another 1000+ for phase2... I cant afford it at the moment because i'm at uni studying Forensic coputing.... and i loads for it as it is....
alibax007 4 years ago
Well, you can always download the EnCe Study Guide PDF (or buy the book I suppose). It is the study guide for people working toward Guidance Software's EnCe Encase certification...
threesandals 4 years ago
@threesandals So Could I recover Original Data from a HD that since 2000 has been formatted over15 times?
bishop102 11 months ago
thanks for posting this, but can i advise you to use a different program in future to record the demo called camstudio.
if you already used this, why it so blured? i can't properly read anything on the screen without skwinting.
gqx001 4 years ago
Yeah, YouTube scales it down quite a bit which is the reason for the "blurryness". The unscaled version that I posted on Freenet looks pretty good. I did use Camtasia Studio BTW.
threesandals 4 years ago