OpenText EnCase
OpenText EnCase: Digital Forensics and Incident Response platform. EnCase Forensic, Endpoint Investigator, Mobile Investigator. Digital investigations and incident analysis.

Key Features
- EnCase Forensic - media analysis, court-ready evidence
- Endpoint Investigator - remote forensics on endpoints
- Endpoint Security - EDR, threat hunting
- Mobile Investigator - mobile device forensics
- Forensic Equipment - hardware for acquisition
Table of Contents
What is OpenText EnCase?
OpenText EnCase is a Digital Forensics and Incident Response (DFIR) platform - tools for conducting digital investigations, analyzing security incidents, and collecting electronic evidence. Industry standard for 25+ years.
Main components:
- EnCase Forensic - desktop forensics, court-ready
- Endpoint Investigator - remote forensics at scale
- Endpoint Security - EDR, threat detection
- Mobile Investigator - iOS, Android forensics
What problem does it solve?
flowchart LR
subgraph Without DFIR
A[Incident] --> B[No tools]
B --> C[Evidence loss]
C --> D[No accountability]
end
subgraph With EnCase
E[Incident] --> F[Fast acquisition]
F --> G[Forensic analysis]
G --> H[Court-ready evidence]
end
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#dc2626,stroke:#b91c1c,color:#fff
style C fill:#dc2626,stroke:#b91c1c,color:#fff
style D fill:#dc2626,stroke:#b91c1c,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
style H fill:#22c55e,stroke:#16a34a,color:#fff
Common problems:
- Security incident - what happened, who, when?
- Suspected insider threat - need evidence
- Malware analysis - how did it get in, what did it do?
- eDiscovery - legal data requests
- HR investigation - employee misconduct
How does EnCase work?
flowchart TD
A[Incident / Request] --> B{Scope?}
B -->|Single system| C[EnCase Forensic]
B -->|Multiple endpoints| D[Endpoint Investigator]
B -->|Mobile| E[Mobile Investigator]
C --> F[Disk image]
D --> G[Remote collection]
E --> H[Mobile extraction]
F --> I[Analysis]
G --> I
H --> I
I --> J[Timeline]
I --> K[Artifacts]
I --> L[Report]
L --> M[Court / HR / Legal]
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#f59e0b,stroke:#d97706,color:#fff
style I fill:#8b5cf6,stroke:#7c3aed,color:#fff
style M fill:#22c55e,stroke:#16a34a,color:#fff
EnCase Components
EnCase Forensic
Desktop forensics
- Disk imaging (E01)
- File system analysis
- Registry, artifacts
- Court-accepted format
Endpoint Investigator
Remote forensics
- Agentless collection
- Enterprise scale
- Triage at speed
- Memory forensics
Endpoint Security
EDR + Response
- Real-time detection
- Threat hunting
- Automated response
- IOC scanning
Mobile Investigator
Mobile forensics
- iOS extraction
- Android extraction
- App data analysis
- Chat recovery
Information Assurance
Compliance monitoring
- Endpoint auditing
- Policy compliance
- Data inventory
- Risk assessment
Forensic Equipment
Hardware
- Tableau write-blockers
- Forensic duplicators
- Mobile adapters
- Portable kits
Incident Response Workflow
flowchart LR
A[1. Detection] --> B[2. Triage]
B --> C[3. Collection]
C --> D[4. Analysis]
D --> E[5. Remediation]
E --> F[6. Reporting]
A --> A1[SIEM alert<br>User report]
B --> B1[Endpoint Investigator<br>Remote triage]
C --> C1[EnCase Forensic<br>Full image]
D --> D1[Timeline<br>Artifacts]
E --> E1[Containment<br>Eradication]
F --> F1[Legal<br>Lessons learned]
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#f59e0b,stroke:#d97706,color:#fff
style C fill:#8b5cf6,stroke:#7c3aed,color:#fff
style D fill:#6366f1,stroke:#4f46e5,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
What can be found?
| Artifact | Information |
|---|---|
| Registry | Installed software, USB history, user activity |
| Event logs | Logins, process execution, security events |
| Prefetch | Program execution history |
| Browser history | URLs, downloads, searches |
| PST/OST analysis | |
| Memory | Running processes, malware, credentials |
| File carving | Deleted files recovery |
| Timeline | Comprehensive activity chronology |
Endpoint Investigator - Enterprise Scale
Remote forensics without physical access:
Traditional forensics
- Physical computer seizure
- One system at a time
- Days/weeks for analysis
- Expensive and slow
Endpoint Investigator
- Remote collection over network
- Thousands of endpoints in parallel
- Triage in minutes
- Enterprise scale
Who is it for?
EnCase MAKES sense when:
- • You have a security/IR team or SOC
- • You conduct internal investigations (HR, fraud)
- • You need court-ready evidence
- • Enterprise with distributed endpoints
- • eDiscovery / legal hold requirements
EnCase DOESN'T make sense when:
- • Small company without dedicated security
- • Only EDR - there are simpler solutions
- • No forensic expertise - outsource to MSSP
EnCase vs competition
| Aspect | EnCase | FTK | X-Ways | Cellebrite |
|---|---|---|---|---|
| Court acceptance | Gold standard | Yes | Yes | Mobile only |
| Enterprise remote | Endpoint Investigator | Enterprise | No | No |
| Mobile | Mobile Investigator | No | No | Market leader |
| Memory forensics | Yes | Limited | Yes | Limited |
| Price | Premium | Mid | Budget | Premium (mobile) |
| Learning curve | Medium | Medium | Steep | Medium |
EnCase advantage:
- 25+ years as standard in court proceedings
- Endpoint Investigator for enterprise scale
- Complete portfolio (disk + memory + mobile + EDR)
- Integration with OpenText security stack
Specifications
| Parameter | Value |
|---|---|
| Platforms | Windows, macOS, Linux |
| Mobile | iOS, Android (via Mobile Investigator) |
| Image formats | E01, Ex01, raw, VHD, VMDK |
| File systems | NTFS, FAT, HFS+, APFS, ext2/3/4, XFS |
| Cloud | AWS, Azure, GCP forensics |
| Certifications | Court-accepted globally |
FAQ
Is EnCase court-accepted? Yes. EnCase Evidence Format (E01) has been the standard in court proceedings worldwide for 25+ years.
Do I need a full image or is triage enough? Triage (Endpoint Investigator) for quick review of many systems. Full image (EnCase Forensic) when you need complete analysis or evidence.
How does remote collection work? Agent or agentless over network. Collects artifacts, memory, selected files without physical access to the machine.
What about encrypted drives? EnCase supports analysis of BitLocker, FileVault, LUKS if you have the key. Without key - limited options.
Do I need training? Yes. EnCase requires forensic expertise. OpenText offers EnCE (EnCase Certified Examiner) certifications.
Does nFlo implement EnCase? Yes. EnCase Forensic, Endpoint Investigator deployments, training, incident response consulting.
Inquire about OpenText EnCase
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
Web Application Penetration Testing
Cybersecurity
One SQL injection = access to entire database. Find vulnerabilities before hackers do.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist