Has your agency upg...
 
Notifications
Clear all

Has your agency upgraded to EnCase V7?

31 Posts
25 Users
0 Likes
2,091 Views
(@angrybadger)
Posts: 164
Estimable Member
 

Jonathan,

Can you elaborate on why that is?

Thanks.

Various reasons, primarily that it's just leagues behind X-Ways Forensics in almost any way you choose to look at it. Also EnCase 7 is just not ready, is it? If you're sticking with the Guidance route that leaves you with EnCase 6, which is fine, especially if you have some decent EnScripts to run on it. But hold on - it's now a legacy product as Guidance have put it out to pasture. A case could perhaps be made that if you've alternatives to hand it would be negligent to currently use EnCase 6 or 7.

If you've alternatives then it's negligent not to use both.

For all its failings Encase has been used in anger for a lot longer by a lot more people than XWays without too many problems.

But version seven certainly has the air of FTK 2 (er 3) to it.

 
Posted : 05/01/2012 4:49 pm
(@jonathan)
Posts: 878
Prominent Member
 

For all its failings Encase has been used in anger for a lot longer by a lot more people than XWays without too many problems.

Agreed, though popularity and longevity are no indicators of quality; in this instance it's more of a marketing win. As I said, if you're currently using EnCase 6 (bugs no longer fixed) or EnCase 7 (which in many people's views is not fit purpose) in your lab when you've superior alternatives to hand that don't have these problems then it's negligent.

 
Posted : 05/01/2012 6:53 pm
minime2k9
(@minime2k9)
Posts: 481
Honorable Member
 

Think this is missing a "We're on 6 and not moving until 7 is right" option

 
Posted : 05/01/2012 7:09 pm
binarybod
(@binarybod)
Posts: 272
Reputable Member
 

How about an option entitled "We moved to Version 7 as soon as we could, we're loving it" ?

Paul

 
Posted : 05/01/2012 7:36 pm
Sonj
 Sonj
(@sonj)
Posts: 7
Active Member
 

V7 removed every single out-of-box feature that works well for fast triaging. Pre-configured conditions, filters, text styles are gone, making it difficult to deploy scratch installations for urgent or dynamic situations.

Selective and repeatable processing (although they claim to be addressing part of this), easy simultaneous review of numerous devices or mounted file structures - all gone. It has removed the easy and very flexible utility of bookmarking overlapping sets of data on the fly that v6 allows.

If you suffer from any RSI from years of using mouse-intensive interfaces, I would not recommend v7. It is more difficult to perform large scale repetitive work that cannot be easily automated due to some inherent human decision/review process.

The designers have decided that mousing from from one side of a widescreen to the other multiple times to deal with ONE ITEM is a good idea. They have grouped functions by similarity not workflow, yet not provided adequate or configurable keyboard shortcuts to bypass an interface that is quite inefficient.

While v6 is fast becoming obsolete due to its lack of recent file system support, weak viewer and out-of-box file signatures, it still limps along ok for our lab, our particular triage-oriented workflow and the vast majority of data we see. It is still our most effective conduit for dumping out user data for proper indexing and for pushing selected artifacts to a toolbox of more up-to-date and effective analytical tools.

Where is the "you will pry v6 from my cold, dead (numb) hands" poll option? D

 
Posted : 06/01/2012 3:10 am
MrKameren
(@mrkameren)
Posts: 6
Active Member
 

Guidance is doing a great job receiving input to improve V7 and make it more user friendly. V7 does have a way to go before it's reached it's potential. Currently in our lab we're using both V6 or V7 dependent on the case details.

 
Posted : 06/01/2012 4:11 am
(@yunus)
Posts: 178
Estimable Member
 

Yes we have upgraded to 7, but we came to conclusion that it is not worth upgrading. They have taken many useful features out. For instance, You can not filter deleted files practically as you were able to do with a single click. You pay for ugrade and you get less than what you have got before.

Is that fair?

 
Posted : 06/01/2012 11:00 pm
ForensicRanger
(@forensicranger)
Posts: 122
Estimable Member
 

We have not upgraded to V7 given that is was released prematurely… perhaps equate it with Microsoft's release of Vista v Windows 7. We had GS come to our office and they gave us the pitch on v7, and many questions were asked by those who attended - particularly as to why some features were removed and why others were cumbersome to find.

Once v7 is -ready-, we'll do the switch, but until such a time, 6.19 remains.

I did not vote as the option I would have chosen (same as minime's) is not available.

 
Posted : 10/01/2012 11:36 pm
zhaan
(@zhaan)
Posts: 50
Trusted Member
 

Guidance is doing a great job receiving input to improve V7 and make it more user friendly. V7 does have a way to go before it's reached it's potential. Currently in our lab we're using both V6 or V7 dependent on the case details.

That will be a first on both counts!

 
Posted : 11/01/2012 5:48 pm
(@shep47)
Posts: 51
Trusted Member
 

Yes and No.

Still using EnCase v6 for its EnScript support (especially the hat full provided by James Crabtree).

Happy with the EnCase v7 processing of BB, iPad (et al) and 'out of the box' Safeboot support (we never had the extra modules for v6). Not happy with the evidence processing (never had time to let it finish!)

Shep

 
Posted : 11/01/2012 10:00 pm
Page 2 / 4
Share: