Storage

Lock IT Down: Track down lost data with EnCase

EnCase can offer full data recovery for companies and clients doing forensic work


With the recent proliferation of storage mediums, users are less likely to keep important data locked away in a file cabinet. While this is good news for the trees, there is always the risk that a hard drive or data disk could become corrupted. When data is lost, it’s the IT professional’s job to discover documents or files buried on a hard drive or data disk. The task might include helping users who have lost their data due to a system failure, or it could be as important as discovering data that is crucial to a complex court case. This burgeoning field is collectively called computer forensics. Computer forensics tools are ideal for solving cybercrimes, accounting fraud, as well as the more common occurrence of accidental destruction of important data files. To help you better understand this type of computer sleuthing, I will share my experience with Guidance Software’s computer forensics tool, EnCase.

Installation
EnCase runs on Windows 98, Me, NT 4.0, 2000, and XP operating systems. The software can acquire and analyze evidence on the following types of file systems: FAT12, FAT16, FAT32, NTFS, HFS, HFS+, CD, EXT2 (Linux), and UFS (UNIX) hard disks and removable media.

I installed and tested the software on a Windows 98 laptop. The installation was very straightforward, requiring just a few clicks of the Next button when the installation wizard presented it. When the installation was complete, I rebooted the system and looked for the icon in the Start menu. However, the icon or text file typically placed on the desktop and Start menu was not visible. I tried installing EnCase again, this time powering down the system completely using Shutdown. Still the icon or text file in the Start menu did not show up. However, when I double-clicked on the program’s executable file (encase3.exe) in the C:\Program Files\EnCase directory, the program launched as expected.

EnCase example
To test the software, I created a document called SEC_Revenue_Statement using Microsoft Word, and entered the following text:
SEC Revenue Statement
In the event of an SEC investigation, please destroy this very important accounting statement regarding our financial operations. 1234567890-=\][';
Big Bad CFO


I saved the Word document to a floppy disk and then proceeded to delete it from the disk. (I did not save it to my hard drive because acquiring the evidence from a 40 GB hard drive is more time-consuming.) Next, I went into EnCase's menu system and selected File | Acquire Evidence. I was prompted to select from the following locations to search for the evidence:
  • ·        Local Devices
  • ·        Parallel Port
  • ·        Network Port
  • ·        Floppy Drives
  • ·        Volumes
  • ·        Physical Disks
  • ·        Palm Pilots

I checked off Local Devices and Floppy Disks. Next, I was prompted to select my drive letter. I selected Floppy Drive A. The date and time were automatically entered by the system. I named the case Fake SEC Investigation, and I put Test Case 1 in the Evidence Number field. Then I entered Looking for SEC_Revenue_Statement in the Notes field (see Figure A).

Figure A


Next, the Analysis Options screen prompted me with the following options for analyzing the data:
  • ·        No
  • ·        Add And Verify

I selected Add And Verify to do a full analysis of the diskette and clicked on Next. The wizard took me to the Output File screen, which offered the following compression choices:
  • ·        None (Fastest, Largest)
  • ·        Good (Slower, Smaller)
  • ·        Best (Slowest, Smallest)

TheOutput File screen also prompts you to enter a password. Located on the same screen, the program automatically put in C:\Program Files\Encase\Test Case 1.E01 in the Evidence File Path field. In the File Segment Size field, the program defaulted to 640. I clicked on the Finish button, and the pop-up screen disappeared. The disk and CPU started cranking away with the EnCase screen flashing the words Creating Evidence File A.

When it finished, I was prompted for my password. After supplying my password, I was asked if I wanted to acquire any more data. I answered No and selected Preview to open the case file. The resulting menus looked pretty interesting. I selected the Keywords tab and typed SEC Revenue Statement. Next, I selected Search from the Tools drop-down menu. The program cranked away for a few minutes and came back with eight Search Hit bookmarks. I clicked on some of them and selected Text from the lower tab menu. Low and behold, I found the contents of my suspicious (and deleted) Word document (see Figure B).

Figure B
My career as a computer forensics investigative analyst looks promising.


EnCase features
After you acquire the evidence, you need to know how to navigate through the remaining EnCase menus. To create a new case, select New on the menu. You'll then be prompted with the screen shown in Figure C.

Figure C
On the File tab, enter the paths for Default Export Folder and Temporary Folder, which already exist on your forensics computer.


When you select the Global tab (see Figure D), you will be prompted for date and time formats, and you’ll be asked if you want to show numbers in hex. By default, the Picture Viewer is enabled.

Figure D


The Script Security tab (see Figure E) is for selecting read, write, create, and delete options for the evidence case. These options are important because once you create the case, you’ll want to make sure that it has not been tampered with. By default, all three are selected. Click OK.

Figure E


As you acquire more data, you can add more evidence to your case by clicking on Add from the top menu. EnCase performs an Acquisition Hash (see Figure F) of the evidence so you can go back and verify that it hasn't been tampered with. You can also see the Last Accessed dates, which might be relevant to your investigation.

Figure F


Lastly, the TimeLine feature (see Figure G) lets you build a sequence of events so you can see what files were accessed and in what order they were accessed during the time leading up to the loss of data.

Figure G


Good enough for the feds
Guidance Software’s customers include the U.S. Treasury Department, the Secret Service, the Immigration and Naturalization Service, and the Bureau of Alcohol Tobacco and Firearms. EnCase's efficiency and capability make it obvious why this tool appeals to forensic investigators and law enforcement. If you need to perform computer forensics for your user base, whether you’re investigating accounting fraud, hacking, or just trying to recover from a user's document disaster, EnCase is a solid bet for full data recovery.

Editor's Picks