Questions tagged [encase]

EnCase is a proprietary forensic software suite.

Wikipedia: https://en.wikipedia.org/wiki/EnCase

3 questions
3
votes
2 answers

Encase forensics .dd

I used Mandiant Intelligent Response to acquire a disk image of a window 7 computer. After it finished it gave me a .dd file. I have been trying to used Encase to analyse the file but when I add the evidence it does not give me the full file…
0
votes
1 answer

What is exact meaning of "Recovered Folders", when after run the isDeleted condition?

Now, I am analyzing some device with using the encase 7. While this work, I set the [condition] to [is Deleted -> True]. After end of run, some files was showing up on encase windows, and each item path was set to {Case Name}{Evidence}{Volume…
W. SONG
  • 33
  • 10
-2
votes
1 answer

Python 3.5 Regular expressions cannot read text file

Would it be a good idea to convert a text file to a doc string (same as literal string) for regular expressions to work? I've tried converting it to a string with str() and using multiline mode in re. I've created a rudimentary script to parse out…
Jimmy
  • 152
  • 11