Course list http://www.c-jump.com/bcc/

Step-by-Step EnCase Media Examination


  1. Case Management
  2. Case File
  3. Evidence File
  4. Creating a New Case
  5. Adding Evidence Files
  6. Check Acquisition MD5 Hash
  7. Initial Directory Structure
  8. Disk Geometry and Partitions
  9. Recovering Deleted Folders and Files
  10. Signature Analysis
  11. View File Signature Analysis Results
  12. Searching Unallocated Space
  13. Next Steps and The Search Warrant
  14. Time Zone Info
  15. Case Processor
  16. Case Processor - Time Zone Info
  17. Case Processor - Recovering Graphics
  18. Case Processor - Find Protected Files
  19. Case Processor - Windows History
  20. Search: Email
  21. Search: Email results - Records Conditions
  22. Search: Internet History
  23. Webmail
  24. Sweeping Bookmark
  25. Bookmarking Images
  26. Creating Reports
  27. Advanced: Disk Geometry Overview
  28. Advanced: Drive Size
  29. Advanced: Partition Information
  30. Advanced: Recovering Deleted Partition
  31. Advanced: Removing Recovered Partition
  32. Hash Library
  33. Hash Library Hierarchy
  34. Hash Set Category
  35. Hash Library Building Steps
  36. Encase 7 processing steps

1. Case Management



2. Case File



3. Evidence File



4. Creating a New Case



5. Adding Evidence Files



6. Check Acquisition MD5 Hash



7. Initial Directory Structure



8. Disk Geometry and Partitions



9. Recovering Deleted Folders and Files



10. Signature Analysis



11. View File Signature Analysis Results



12. Searching Unallocated Space



13. Next Steps and The Search Warrant



14. Time Zone Info



15. Case Processor



16. Case Processor - Time Zone Info



17. Case Processor - Recovering Graphics



18. Case Processor - Find Protected Files



19. Case Processor - Windows History



20. Search: Email



21. Search: Email results - Records Conditions



22. Search: Internet History



23. Webmail



24. Sweeping Bookmark



25. Bookmarking Images



26. Creating Reports



27. Advanced: Disk Geometry Overview



28. Advanced: Drive Size



29. Advanced: Partition Information



30. Advanced: Recovering Deleted Partition



31. Advanced: Removing Recovered Partition



32. Hash Library


33. Hash Library Hierarchy



34. Hash Set Category



35. Hash Library Building Steps


  1. Search -> check Compute hash value. This generates MD5 fingerprints for all allocated files.

  2. Select (blue-check) files to be included in a hash set. Right-click in the table view area and click Create Hash Set...

  3. Specify hash set name and category.

  4. View -> Hash Sets -> Select (blue-check) desired sets -> right-click in the table view area and click Rebuid Library...

  5. The Library is shared between cases. Click Search -> check Compute hash value and execute this on any blue-check-selected files that you wish to analyze. Use Selected items only option in the search box as necessary.

  6. As a result of the search, the hash values, hash set names, and hash set category columns are indicated in the table view pane of the allocated files. Use green home plate selection to flatten the view as necessary.

  7. Follow Lesson 15, page 157 of EnCase Student's guide to learn how to apply filters on computed hash sets and how to document the findings.

     


36. Encase 7 processing steps

Evidence Processor (EP)
options  
Execution
Steps  
View
Results                                                 
Additional
Steps
PE Recover Folders Only for FAT and NTFS Entries Tab
Tree View Panel
.Lost Files
.Recovered Folders
       
PE Expand Compound Files Includes ZIP, DOCX, etc.    
PE Find Email Search for specific email storage files PST/PBX/MBX etc. Records Tab Evidence Tab
In Table View right-click and View File Structure
Webmail:
PE File Carver
Carve HTML Carve Webmail Files
Records Tab    
PE Find Internat Artifacts
Search Unallocated Space
Parses index.dat of IE and similar files of other browsers Records Tab  
Evidence Tab   Filter...   Results Tab View a subset of evidence items
Search Tab
Index Search
Use AND and OR logic. See Encase Help for additional query options  
Uses transcript of PDF and other compound files       Search Tab
Results Tab

In the bottom View area, use
Find Next
Previous Item
Next Item
to iterate through the matching items.
Use green Play button to execute index query.

Note that results are displayed in the Search Tab but also duplicated in the Results Tab. Supposedly, the results tab appears "less cluttered"
PE Keyword Search
or Evidence Tab
Raw Search
Global keyword search. Keyword are saved in the case cache Search Tab
Keyword hits
Results Tab  
Use green Play button to execute keyword query.

The keywords must be selected to be included in the query  
Entries Tab
Tree View
Selected Items
Raw Search
allows to search selectively inside the evidence tree. See textbook p 354 for details.

Options:
Search Entry Slack allows searching for FAT32 directory entries and inside file slack
Search Initialized Size for NTFS only. Searches only what user would see in the file.
Undelete Entries Before Searching searches across cluster boundaries
Search Tab
Keyword hits
Results Tab
Use green Play button to execute keyword query.

Note: the keywords must be saved in a separate .keyword file

The keywords must be selected to be included in the query