Access Data Forensics Toolkit V. Encase: Digital Essay


Access Data Forensics Toolkit v. EnCase: Digital or computer forensics is currently one of the rapidly growing and significant industries because of technological advancements. The growth and significance of this industry has been enhanced by the increase in digital crimes, which has contributed to the need for organizations to adopt quick and reliable tools to collect and offer digital evidence. Digital forensic teams need some items in the forensic toolkits regardless of whether these teams are part of the organization or law enforcement agency. One of the most important processes in computer forensics is drive acquisition, which must be a forensically relevant sound image i.e. flat file bit stream image. In addition, the process also requires volatile data in order to enhance the findings of the process. As digital forensics continues to grow and become important, there are various toolkits that have been developed including Forensic Toolkit (FTK) by AccessData and EnCase Forensic.

FTK by AccessData:

AccessData Forensic Toolkit is a platform developed for stability, ease-of-use, and speed and provides wide-ranging processing and indexing straight forward in order to improve the speed of filtering and searching with any other product or item ("Forensic Toolkit -- FTK," n.d.). Since this toolkit exposes more data within a short period of time and improves visualization and explicit image detection, it is a court-accepted digital investigations platform. The other strength of Forensic Toolkit is that it's a database-driven, enterprise-class platform that enables investigators to deal with huge data sets because of its stability and ability to upgrade easily.

EnCase Forensic:

Encase Forensic is a common software for computer forensics, which is packaged with several features that support the four stages of digital investigations. Since the software is one of the most popular means for computer forensics,...


EnCase is a faster forensic investigation tool that is renowned for increased processing speeds and inclusiveness of the indexed results.
Features of these Tools:

FTK is a forensic tool that develops images, evaluates the registry, decrypts files, cracks passwords, performs an investigation, identifies steganography, and provides a report within a single solution. The tool also has the ability to recover passwords from more than 80 applications, support huge data sets, enables automated recovery during pre-processing, easy-to-use graphical user interface, and multi-data views ("Top Forensics Tools for Business," 2010). AccessData Forensic Toolkit supports searches of different types of data such as steganography, passwords, e-mail, and computer data and files.

On the contrary, EnCase Forensic acquires data in a forensically-relevant way using software with an unequaled record in courts throughout the globe. The software works on various operating systems including Linux, Solaris, AIX, Windows, and OS X. EnCase has several reporting options that support quick report preparation and allows non-investigators such as attorneys to review options and evidence. Similar to AccessData FTK, EnCase software handles huge data sets and produces court-accepted information.

Costs of the Two Programs and Gathering Digital Evidence from a Cell Phone:

AccessData Forensic Toolkit recently increased its price and software maintenance to 30% of the license price. As a result, FTK's license and first-year maintenance costs $5,200, which is 44% higher than the cost of EnCase license and maintenance of $3,600. Unlike, EnCase, FTK's price are even higher because of the need for significantly improved hardware that increases its overall ownership cost. While every new version of EnCase Forensic software has additional valuable technology and…

