Field Intelligence Model    

Brochures:
EnCase Field Intelligence Model(PDF)
Whitepapers:

Restore Validation (PDF)

EnCase Forensic Hardware Requirements (PDF)

Computer Hardware Recommendations for EnCase Forensic and EnCase Enterprise (PDF)

CLICK HERE TO SEE ALL WHITEPAPERS

 

   
Untitled Page > products and services   > company   > resources   > support   > message boards
Modules Hardware

Home > EnCase Field Intelligence Model

About EnCase® Field Intelligence Model
How it Works
Detailed Product Description (PDF)
System Requirements
Screenshots


The Field Intelligence Model is the Tool of Choice for a Variety of Investigations:

  1. Incident response investigations of static and volatile data
  2. The search and seizure of specific computer files on live servers
    • bank records
    • business records and financials
    • email stores
  3. Acquisition of files inside open encrypted volumes
    • terrorism
    • financial fraud
  4. The acquisition of complete drive images on live machines.
  5. Probation and parole computer searches
    • Child pornography
    • Sex crimes
    • Identity theft
    • Hacking

The Field Intelligence Model (FIM) is an investigative solution available only to local law enforcement. Based on the powerful EnCase® Forensic, this network-enabled investigative solution dramatically simplifies and accelerates field investigations of network-connected computers and servers. The FIM offers investigators powerful capabilities to search computers across a network and analyze all of the relevant information, including volatile data that is traditionally lost during forensic investigations.

  • Acquire data in a forensically sound manner using software with an unparalleled record in courts worldwide.
  • Logical Evidence Files allow investigators to acquire only relevant data, preserving metadata on an individual-file basis, which eliminates the need to capture entire hard drives.
  • Investigate and analyze multiple platforms — Windows, Linux, AIX, BSD, OS X, Solaris and more — using a single tool.
  • Securely investigate/analyze computer, while they're up and running, at a disk level.
  • Overcome the challenges associated with RAID arrays and encrypted volumes by acquiring evidence from live servers.
  • Discretely carry out investigations without alerting suspects.
  • Transfer evidence files directly to other parties, such as legal representatives, as necessary.
  • Quickly triage machines to determine if incriminating evidence exists before acquiring the data.

Capture and analyze volatile data, including active network sessions, live registry, open files and running processes with the EnCase SnapShot capability. LEARN MORE.



REQUEST MORE INFORMATION
  Bundled Solutions
EnCase ProSuite
 

Hardware, Software, Training and Support with EnCase Cybercrime Arsenal

 

 

© 2002-2007 Guidance Software, Inc. All Rights Reserved.
Privacy Statement | Historical Information | Contact Us | Careers | Mailing List | Resellers