EnCase Enterprise v...
 
Notifications
Clear all

EnCase Enterprise vs ProDiscover

28 Posts
11 Users
0 Reactions
5,696 Views
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Can you please tell me what artifacts/files will indicate if Encase Enterprise has been deployed on a PC, and also what to look for to detect if an image has been taken of a machine remotely or viewed remotely?

Any help greatly appreciated

I'm sure it would be, but I do not have EEE, and can therefore not provide accurate information. Such is the way of the "community"…many want information handed to them, but few are willing to pony up any support (not just money) to further such things.

Harlan


   
ReplyQuote
(@jango)
Eminent Member
Joined: 19 years ago
Posts: 26
 

ddow, you are correct that I have not posted much. I have been a long time reader and have found the information here extremely useful. I am not a target. I work in a fraud department of a very large company and I currently have an EnCase Forensic V6 license (via my company). I use this for physical acquisitions at remote locations where EE cannot reach. My company also have EE v6 but I've only used EE v5 a few times only.

In saying all this I am not a files systems guru or techie, therefore that's why I asked how I can detect artifacts of a servlet deployment (which should be every machine in my company under normal coreload) and also artifacts indicating EE remote acquisition or image viewing.

BTW, I have also completed the EnCase Intermediate course 2 years ago.
Any help would be appreciated.


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
 

Saw you guys bring up LiveWire. LiveWire is made by the company Cyber Security found at cyberstc.com and you'll see a lot more OnlineDFS and a lot less LiveWire after this month.

3.6 is going to be out soon with a lot of great updates. I'm honestly surprised more people don't know about it.


   
ReplyQuote
(@jango)
Eminent Member
Joined: 19 years ago
Posts: 26
 

Can anyone help me out here?


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Jango…with what, specifically?


   
ReplyQuote
(@jango)
Eminent Member
Joined: 19 years ago
Posts: 26
 

Can you please tell me what artifacts/files will indicate if Encase Enterprise has been deployed on a PC, and also what to look for to detect if an image has been taken of a machine remotely or viewed remotely?


   
ReplyQuote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

You could build a fresh machine, deploy EE on it, and check to see what changed.

Since you've got valid licenses, you could call tech support and ask them, too.

-David


   
ReplyQuote
(@apcsbz)
New Member
Joined: 12 years ago
Posts: 4
 

I would like to see more details about the differences and similarities. Like File formats, what can be red from other applications, the process and etc


   
ReplyQuote
Page 3 / 3
Share: