Skip to content
Cybersecurity OpenText

OpenText EnCase

OpenText EnCase: Digital Forensics and Incident Response platform. EnCase Forensic, Endpoint Investigator, Mobile Investigator. Digital investigations and incident analysis.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Key Features

  • EnCase Forensic - media analysis, court-ready evidence
  • Endpoint Investigator - remote forensics on endpoints
  • Endpoint Security - EDR, threat hunting
  • Mobile Investigator - mobile device forensics
  • Forensic Equipment - hardware for acquisition
Available now
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Send inquiry
Table of Contents

What is OpenText EnCase?

OpenText EnCase is a Digital Forensics and Incident Response (DFIR) platform - tools for conducting digital investigations, analyzing security incidents, and collecting electronic evidence. Industry standard for 25+ years.

Main components:

  • EnCase Forensic - desktop forensics, court-ready
  • Endpoint Investigator - remote forensics at scale
  • Endpoint Security - EDR, threat detection
  • Mobile Investigator - iOS, Android forensics

What problem does it solve?

flowchart LR
    subgraph Without DFIR
        A[Incident] --> B[No tools]
        B --> C[Evidence loss]
        C --> D[No accountability]
    end

    subgraph With EnCase
        E[Incident] --> F[Fast acquisition]
        F --> G[Forensic analysis]
        G --> H[Court-ready evidence]
    end

    style A fill:#dc2626,stroke:#b91c1c,color:#fff
    style B fill:#dc2626,stroke:#b91c1c,color:#fff
    style C fill:#dc2626,stroke:#b91c1c,color:#fff
    style D fill:#dc2626,stroke:#b91c1c,color:#fff
    style E fill:#22c55e,stroke:#16a34a,color:#fff
    style F fill:#22c55e,stroke:#16a34a,color:#fff
    style G fill:#22c55e,stroke:#16a34a,color:#fff
    style H fill:#22c55e,stroke:#16a34a,color:#fff

Common problems:

  • Security incident - what happened, who, when?
  • Suspected insider threat - need evidence
  • Malware analysis - how did it get in, what did it do?
  • eDiscovery - legal data requests
  • HR investigation - employee misconduct

How does EnCase work?

flowchart TD
    A[Incident / Request] --> B{Scope?}
    B -->|Single system| C[EnCase Forensic]
    B -->|Multiple endpoints| D[Endpoint Investigator]
    B -->|Mobile| E[Mobile Investigator]

    C --> F[Disk image]
    D --> G[Remote collection]
    E --> H[Mobile extraction]

    F --> I[Analysis]
    G --> I
    H --> I

    I --> J[Timeline]
    I --> K[Artifacts]
    I --> L[Report]

    L --> M[Court / HR / Legal]

    style A fill:#dc2626,stroke:#b91c1c,color:#fff
    style B fill:#f59e0b,stroke:#d97706,color:#fff
    style I fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style M fill:#22c55e,stroke:#16a34a,color:#fff

EnCase Components

EnCase Forensic

Desktop forensics

  • Disk imaging (E01)
  • File system analysis
  • Registry, artifacts
  • Court-accepted format

Endpoint Investigator

Remote forensics

  • Agentless collection
  • Enterprise scale
  • Triage at speed
  • Memory forensics

Endpoint Security

EDR + Response

  • Real-time detection
  • Threat hunting
  • Automated response
  • IOC scanning

Mobile Investigator

Mobile forensics

  • iOS extraction
  • Android extraction
  • App data analysis
  • Chat recovery

Information Assurance

Compliance monitoring

  • Endpoint auditing
  • Policy compliance
  • Data inventory
  • Risk assessment

Forensic Equipment

Hardware

  • Tableau write-blockers
  • Forensic duplicators
  • Mobile adapters
  • Portable kits

Incident Response Workflow

flowchart LR
    A[1. Detection] --> B[2. Triage]
    B --> C[3. Collection]
    C --> D[4. Analysis]
    D --> E[5. Remediation]
    E --> F[6. Reporting]

    A --> A1[SIEM alert<br>User report]
    B --> B1[Endpoint Investigator<br>Remote triage]
    C --> C1[EnCase Forensic<br>Full image]
    D --> D1[Timeline<br>Artifacts]
    E --> E1[Containment<br>Eradication]
    F --> F1[Legal<br>Lessons learned]

    style A fill:#dc2626,stroke:#b91c1c,color:#fff
    style B fill:#f59e0b,stroke:#d97706,color:#fff
    style C fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style D fill:#6366f1,stroke:#4f46e5,color:#fff
    style E fill:#22c55e,stroke:#16a34a,color:#fff
    style F fill:#22c55e,stroke:#16a34a,color:#fff

What can be found?

ArtifactInformation
RegistryInstalled software, USB history, user activity
Event logsLogins, process execution, security events
PrefetchProgram execution history
Browser historyURLs, downloads, searches
EmailPST/OST analysis
MemoryRunning processes, malware, credentials
File carvingDeleted files recovery
TimelineComprehensive activity chronology

Endpoint Investigator - Enterprise Scale

Remote forensics without physical access:

Traditional forensics

  • Physical computer seizure
  • One system at a time
  • Days/weeks for analysis
  • Expensive and slow

Endpoint Investigator

  • Remote collection over network
  • Thousands of endpoints in parallel
  • Triage in minutes
  • Enterprise scale

Who is it for?

EnCase MAKES sense when:

  • You have a security/IR team or SOC
  • You conduct internal investigations (HR, fraud)
  • You need court-ready evidence
  • Enterprise with distributed endpoints
  • eDiscovery / legal hold requirements

EnCase DOESN'T make sense when:

  • Small company without dedicated security
  • Only EDR - there are simpler solutions
  • No forensic expertise - outsource to MSSP

EnCase vs competition

AspectEnCaseFTKX-WaysCellebrite
Court acceptanceGold standardYesYesMobile only
Enterprise remoteEndpoint InvestigatorEnterpriseNoNo
MobileMobile InvestigatorNoNoMarket leader
Memory forensicsYesLimitedYesLimited
PricePremiumMidBudgetPremium (mobile)
Learning curveMediumMediumSteepMedium

EnCase advantage:

  • 25+ years as standard in court proceedings
  • Endpoint Investigator for enterprise scale
  • Complete portfolio (disk + memory + mobile + EDR)
  • Integration with OpenText security stack

Specifications

ParameterValue
PlatformsWindows, macOS, Linux
MobileiOS, Android (via Mobile Investigator)
Image formatsE01, Ex01, raw, VHD, VMDK
File systemsNTFS, FAT, HFS+, APFS, ext2/3/4, XFS
CloudAWS, Azure, GCP forensics
CertificationsCourt-accepted globally

FAQ

Is EnCase court-accepted? Yes. EnCase Evidence Format (E01) has been the standard in court proceedings worldwide for 25+ years.

Do I need a full image or is triage enough? Triage (Endpoint Investigator) for quick review of many systems. Full image (EnCase Forensic) when you need complete analysis or evidence.

How does remote collection work? Agent or agentless over network. Collects artifacts, memory, selected files without physical access to the machine.

What about encrypted drives? EnCase supports analysis of BitLocker, FileVault, LUKS if you have the key. Without key - limited options.

Do I need training? Yes. EnCase requires forensic expertise. OpenText offers EnCE (EnCase Certified Examiner) certifications.

Does nFlo implement EnCase? Yes. EnCase Forensic, Endpoint Investigator deployments, training, incident response consulting.

Inquire about OpenText EnCase

Contact your product specialist and get a custom quote.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist