Beginner Encase que...
 
Notifications
Clear all

Beginner Encase question and problem

7 Posts
5 Users
0 Reactions
2,401 Views
(@joey2011)
Active Member
Joined: 14 years ago
Posts: 9
Topic starter  

I'm a beginner with Encase and I am starting to practice with it now. I created a new case, and then did an acquire for a local drive that I mounted. It took about 6 hours and then it was complete. I clicked on the + sign next to the listed drive, and nothing.

I thought that by clicking on the + sign next to the acquired drive it would expand and show you the folders? Why is it not showing the folders?

I look in the area that I saved the data to, and I see the E01 and all the other evidence files there, but again, I don't see the list of folders.

Thanks for any help.


   
Quote
(@Anonymous 6593)
Guest
Joined: 17 years ago
Posts: 1158
 

I'm a beginner with Encase …

What version are you using?

I created a new case, and then did an acquire for a local drive that I mounted. It took about 6 hours and then it was complete. I clicked on the + sign next to the listed drive, and nothing.

Some versions of EnCase Forensic v.6 occasionally lost contact with the dongle. When that happens, the case looks empty. Or … you may have run EnCase in acquiry mode – in which all you can do is acquiry. If that is the case, just make sure your dongle is recognized by both the computer and by EnCase.


   
ReplyQuote
(@kbertens)
Trusted Member
Joined: 13 years ago
Posts: 88
 

Indeed it looks like your dongle is not properly connected.
The name of the Encase window (above your File, Edit, View menu's) shows you "Encase Acquisition" or "Encase Forensic".
Also have a look at the Help menu…about Encase. Your dongle ID must be shown here.


   
ReplyQuote
sodick
(@sodick)
Active Member
Joined: 17 years ago
Posts: 5
 

I also think its your dongle,……restarting EnCase will solve that problem.
also,…on previewing the drive,..could you see any folders then..?


   
ReplyQuote
(@crashed)
Active Member
Joined: 15 years ago
Posts: 14
 

If you have found that it isn't your dongle, with some memory cards that have been acquired there may be the need to add a partition to enable you to see the data.
Using version 5.05j (Yes some people still use it!) select the disk tab and right click on the top left box (0000000) and select add partition. There will be a default value already entered, click ok. This will bring up a new value. Enter this value and hopefully your data will now appear.

crashed


   
ReplyQuote
sodick
(@sodick)
Active Member
Joined: 17 years ago
Posts: 5
 

What version of EnCase are you using…?


   
ReplyQuote
(@joey2011)
Active Member
Joined: 14 years ago
Posts: 9
Topic starter  

It turned out to be the dongle.

I had just assumed (yes, bad thing to do) that the red light on the dongle means that it was installed and working. Once I went into the device manger and did an update on the driver for the dongle, it ran the update, and then I started up Encase in full mode.

Thanks for the great advice everyone.


   
ReplyQuote
Share: