EnCase v7.08 近日正式发布,7.08增加了Evidence Processor Manager以及Evidence Processor,不仅可以在本地实现证据处理队列,也支持了通过网络进行分布式证据处理的方式。

以下是Release Note,更新软件下载地址集中于置顶帖中。


What’s New in Version 7.08

  • Evidence Processor Manager
  • Evidence Processor Enhancements
    • Augmented File Carving for Images
    • New Evidence Processor Lock/Unlock Flexibility
  • Encryption Support Updates
  • Windows Resilient File System (ReFS) Support
  • Solaris Volume Manager Support
  • Improved Hash Library Management
  • Macintosh OS X Disk Image Support
  • Safari Internet Artifact Updates
  • Smartphone OS Application Support
  • Usability Enhancements
    • Create Tags Using Keyboard Shortcuts
    • Create Logical Evidence Files from Search Results
    • Improved Email Alternate Body Handling

Evidence Processor Manager
The new Evidence Processor Manager allows for distribution and control of evidence processing for one or more EnCase Examiners or EnCase Processors.

With the Evidence Processor Manager, you can simplify evidence processing and acquisition by:

  • Queuing evidence in the jobs list to be processed.
  • Prioritizing the execution of evidence to be processed.
  • Distributing the processing workload across multiple processing nodes. Any available node picks up the next job in the queue for the rapid processing of evidence.

Evidence Processor Enhancements
File Carver
The File Carver augments existing file carving capabilities by using Windows Graphics Device Interface (GDI) libraries to accurately carve images according to their sizes and file types. GDI libraries identify the actual length of the file to be carved, resulting in increased probability of carving high fidelity images.

New Evidence Processor Lock/Unlock Flexibility
Evidence Processor now gives you the following options so you can designate only the evidence that you want specifically processed:

  • During initial processing, File Signature Analysis can be turned On or Off. The default is On.
  • While running Evidence Processor with an existing evidence cache
    • Keyword Search can be turned On or Off
    • Recover Folders can be turned On if it was previously turned Off

Encryption Support Updates
EnCase Version 7.08 provides the following support for encryption products:

  • Sophos SafeGuard Easy and Enterprise 6 (32-bit only)
  • McAfee Endpoint Encryption 7.0 (32-bit only)
  • Check Point Full Disk Encryption 8 (OS X and Windows)

Windows Resilient File System (ReFS) Support
EnCase supports the investigation of machines running the Windows 8 operating system. This includes the ability to acquire and parse allocated files and folders from the ReFS file system.

Solaris Volume Manager
EnCase now supports Solaris Volume Manager (SVM), to parse and investigate logical volumes on Solaris 9 and 10 computers.

Improved Hash Library Management
The Manage Hash Library function now allows you to:

  • Select a hash set to work with
  • View the contents of a hash set
  • Delete individual items from a hash set

Macintosh OS X Disk Image Support
The following Macintosh OS X media types are now supported by EnCase:

  • DMG format
  • Sparse image format
  • Sparse bundle format

Macintosh File Value is a wrapper on top of DMG or sparse image files. All three types of media can be encrypted via either AES-128 or AES-256. EnCase currently supports images encrypted with AES-128, only.

EnCase now supports the following DMG formats:

  • UDZO (zip compression algorithm)
  • UDBZ (BZip2 compression algorithm)
  • UDCO (Apple-proprietary ADC compression algorithm)

Safari Internet Artifact Updates
EnCase supports Safari Versions 5 and 6 including cookie and cache artifacts.

Smartphone OS Application Support 
The following list shows software applications supported by EnCase, arranged by operating system.

Android

  • Gmail
  • Yahoo mail
  • GTalk
  • Facebook
  • Twitter
  • Google+
  • Google Now
  • Google Docs
  • Dropbox
  • Chrome Browser

iPhone

  • Google Maps
  • Apple Maps
  • Google Plus

Usability Enhancements
Create Tags Using Keyboard Shortcuts
You can now create tags using keyboard shortcuts. Hot keys are assigned to the first ten tags (Alt-0 to Alt-9)

Search Results Exported to Logical Evidence Files
You can now export items in a set of search results to a logical evidence file (LEF). Search results may contain both entries and records. When you export search results containing only entries or containing only records, EnCase generates a single LEF. When you export search results containing both entries and records, EnCase generates two LEFs.

Improved Email Alternate Body Handling
When email systems append a plain text version of the email together with the HTML/rich text version, this text is called an "alternate body." Formerly, EnCase treated this as an attachment to the message, and displayed an attachment paper clip icon. Now, when an alternate body is the only attachment to an email message, EnCase displays a standard email icon, rather than the paperclip icon.

[DFNews] EnCase v7.08发布的更多相关文章

  1. EnCase v7 search hits in compound files?

    I used to conduct raw search in EnCase v6, and I'd like to see if EnCase v7 raw search could hit key ...

  2. [DFNews] What's coming in EnCase 7.08?

    论版本变化速度,AD绝对首屈一指,从FTK 4到现在的FTK 5也不过两年多时间,EnCase近期(初步预计8月初)将推出V7的新版本7.08,下面是一些新功能: Evidence Processor ...

  3. [DFNews] EnCase 更新至 v7.10

    有加密狗的可以注册接收邮件下载 暂时只有英文版 前几天讲课还说到,EnCase的Template倒是好,但是稍微改一下Case Template自带的Bookmark结构,那么Report就看不到了, ...

  4. EnCase v7 could not recognize Chinese character folder names / file names on Linux Platform

    Last week my friend brought me an evidence file duplicated from a Linux server, which distribution i ...

  5. jquery ajax jsonp跨域调用实例代码

    今天研究了AJAX使用JSONP进行跨域调用的方法,发现使用GET方式和POST方式都可以进行跨域调用,这里简单分享下,方便需要的朋友 客户端代码 复制代码 代码如下: <%@ Page Lan ...

  6. IaaS层市场科普

    简介 这是本博客系列云计算相关文章中的第二篇,所有文章请参考: 博客所有文章 本文主要介绍了一下当前IaaS层市场上的几个主要角色,这几个角色的历史发展以及现状. 开源市场 CloudStack 一句 ...

  7. zwPython,字王集成式python开发平台,比pythonXY更强大、更方便。

    zwPython,字王集成式python开发平台,比pythonXY更强大.更方便. 更强大,内置opencv.cuda/opencl.NLTK自然语言.pygame游戏设计等多个重量级模块库. 更方 ...

  8. RxJS 6有哪些新变化?

    我们的前端工程由Angular4升级到Angular6,rxjs也要升级到rxjs6.  rxjs6的语法做了很大的改动,幸亏引入了rxjs-compact包,否则升级工作会无法按时完成. 按照官方的 ...

  9. linuxtoy.org资源

    https://linuxtoy.org/archives.html Archives 在 Android 系统上安装 Debian Linux 与 R (2015-07-14) Pinos:实现摄像 ...

随机推荐

  1. php读取json时无数据(为空)的解决方法

    在使用PHP调用一些json接口文件时 如果使用 file_get_contents 获取页面json数据后 再使用json_decode()解析后 数据无法正常输出 这是的返回值为null 这是由于 ...

  2. 2016年4月面试题(Unity)

    一. C#中值类型和引用类型的区别? A: 值类型的数据存储在内存的栈中:引用类型的数据存储在内存的堆中,而内存单元中只存放堆中对象的地址. 值类型存取速度快,引用类型存取速度慢 值类型表示实际数据, ...

  3. 浅谈GPU

    Programmable Graphics Processing Unit(GPU),可编程图形处理单元,可编程图形硬件. 98年NVIDIA的modern GPU研发成功,使用晶体管(transis ...

  4. <随便写写>

    # Markdown用法 整理

  5. Linux IO漫谈

    本文为原创,转载请注明:http://www.cnblogs.com/gistao/ Background IO可能是我们接触最频繁的系统调用,比如printf到终端,send content到对端, ...

  6. 前端工具-Sublime、WebStorm-快捷方式使用

    记录下我工作中使用的编辑软件Sublime和WebStorm用到的快捷方式来水一贴(*^__^*) Sublime是我使用的最长时间的编辑器了,也熟悉了一些快捷键使用. 1.Ctrl + /  --- ...

  7. 【转】以 java 为例,总结下 appium 里的一方法的使用心得

    转自:http://testerhome.com/topics/1043 1.关于没有name,没有ID的元素的定位---通用篇解题思路:因为没有name,id:其实剩下的选择已不多,要么xpath, ...

  8. html中的空格显示问题

    像这种,从后台查询出来的数据中间有好几个空格,但在页面上显示的时候就只剩一个空格了,这种显示肯定是不合适的,相关的html代码如下: <c:forEach items="${list} ...

  9. java中常见的几种Runtimeexception

    转自http://blog.csdn.net/qq635785620/article/details/7781026 一般面试中java Exception(runtimeException )是必会 ...

  10. 正则表达式测试器 beta_

    说明:"言简意赅".简而从之:如题※网上已经有很多正则的测试工具了※感谢小Z推荐了一款非常好的(但是个别子匹配项多时卡顿.应该是我的表达式问题)故而花了点时间照着“抄”了一个,并配 ...