EnCase 是數位鑑識領域中,非常有名的一套軟體,為Guidance Software公司生產, 該公司成立於1997年,開發團隊的成員多半是具有數位鑑識人員(專家)背景. EnCase支援各種作業系統及檔案系統,為國際間普遍被採用的專業電腦鑑識軟體。
功能介紹
Forensics report (產生鑑識報告)
Image gallery (圖片檔案快速瀏覽)
View Registry (檢視登錄檔)
CDFS support (支援CDFS格式)
Password recovery (密碼破解,為PLSP選購模組)
Keyword search (關鍵字搜尋)
E-mail search (電子郵件搜尋)
NTFS support (支援NTFS格式)
FAT 16/32 support (支援FAT16/32格式)
EXT2/3 support (支援EXT2/3格式)
File Recovery (刪除檔案復原)
Validate Image (映像檔驗證)
Duplicate (建立數位證物映像檔)
Wipe Disk (清理磁碟紀錄)
Web History/Cookie/Cache/URLtyped (網路瀏覽紀錄檢視)
Text indexing (檔案建立索引)
Encase 64-Bit support
DBX/PST/EDB/NSF (電子郵件檢視及搜尋功能)
支援繁/簡體中文及各國多語系的文件搜尋
更新介紹
What’s New with EnCase Forensic v22.3
With the release of EnCase Forensic v22.3, digital forensic investigators can now take advantage of AFF4 functionality. AFF4, or the advanced forensics file format, is an open-source format used for the storage of digital evidence and data. EnCase Forensic now supports both physical and logical reading of images, meaning an investigator can copy an entire image or only select portions of an image from another investigative tool into the EnCase format for fast, deep-drive investigations to ensure they have the information advantage needed to get to the truth faster and make the world a safer, more secure place.
EaseFilter
Easecilter Inc. 公司是一家專門從事Windows檔案系統篩選器驅動程式開發的公司。它可以為各種功能提供架構師、實現和測試檔案系統篩檢程式驅動程序。它還可以提供多個級別的幫助,以滿足您的特定需求:為現有的檔案系統篩選器驅動程序提供諮詢服務;自定義SDK以滿足您的需求;使用SDK原始程式碼創建您自己的篩選器驅動程式。
File System Monitor Filter Driver SDK
EaseFilter File System Monitor Filter Driver SDK is a component which can monitor the file system I/O activities on the fly, to know who and when your files were accessed.
File System Control Filter Driver SDK
EaseFilter File System Control Filter Driver SDK is a component which can protect your files being accessed by unauthorized users and processes. file level encryption in kernel on-the-fly
File System Encryption Filter Driver SDK
EaseFilter File system encryption filter driver SDK is a component which provides transparent file level encryption in kernel on-the-fly.
CloudTier Storage Tiering SDK
CloudTier Storage Tiering SDK (also Hierarchical Storage Management, HSM) is a data storage technique that automatically moves data between high-cost and low-cost storage media, is the automated progression or demotion of data across different tiers of storage devices and media. The CloudTier Storage Tiering SDK provides you an automatic way of managing and distributing data between the different storage, allows the automated data movement between the tiers of storage based on the defined rules and policies.
FileAudit,為您有力管理Windows伺服器的工具。
主動追蹤、查核對每個檔案與資料夾的存取活動,提出報告與警示訊息。
即時監控
隨時追蹤、偵測並記錄您Windows系統上的檔案存取活動
(讀取/寫入/刪除/權限變更/屬性改變……等等)
自動E-mail警示
監控到特定事件發生時,發出警示郵件,防堵安全漏洞(來自黑名單用戶或特定IP之存取、資料刪除記錄、大量複製或移動資料等等,可由用戶自訂)
智慧型管理
排程E-mail報告,發佈對於各項主題之紀錄彙總(存取路徑、檔案類型、行為分類、存取IP來源),協助擬定管理方針。
另外創建帳戶
給非IT審核人使用,為無管理權限人員(外聘等)另外設定帳戶,讓他們發揮專業與自主性,而不影響企業隱私與安全。
更新介紹
FileAudit 6.5
New: Get an overview of your FileAudit alert history for clear visibility into potential issues
FileAudit alert history reports spare you the pain of scrolling through FileAudit alert emails to spot patterns and identify issues. Now, your alert history comes together in one place, so you can:
Cut the noise with powerful filters to zoom in on the information you need and more easily catch issues.
Get actionable information to:
Spot potential security risks when a user sets off repeated alerts or regularly attempts access outside of normal working hours
Identify needs for more end-user training or communication to reduce future alerts
Improved: The “Database Manager” tile is now “Maintenance”
You’ll notice that the Database Manager tile is now Maintenance, allowing for a new update that allows audit maintenance (details below).
New: Ensure compliance with scheduled, automatic maintenance of audit configuration on audited servers and paths
In the “Maintenance” tile, you’ll see a new “Audit” tab. Now, you can schedule regular maintenance of your audit configuration on audited servers and paths. These maintenance tasks check that your audit configurations have not been modified or overwritten by a GPO, and reconfigure them if necessary.
New: Opt for OAuth2 authentication for the mailbox you use for FileAudit alerts
If you use a Google or Microsoft mailbox for FileAudit alerts, you can now replace SMTP authentication with the more modern OAuth2 authentication protocol.
Improved: Speed up your FileAudit reporting
You can now spend less time on reporting since your FileAudit reports now load faster, use less service memory, and have no impact on GUI.
Improved: Solve MSP web communication problems faster
A more detailed error message now allows you spot the problem faster when you have a web communication issue accessing and/or setting up a new MSP license key.
FinalCode 是一種文件加密/跟踪解決方案,允許您加密重要文件,跟踪其使用情況,甚至遠程刪除它們。當文件發送到公司外部時,使用FinalCode可以防止重要信息(例如技術數據,項目建議書,設計圖紙和客戶信息)的洩漏。
FinalCode的工作原理
FinalCode是一種文件安全雲端服務,旨在管理在公司外部交付的文件。
它由加密/查看文件的FinalCode Client和管理文件權限和其他任務的FinalCode Server組成。
更新介紹
最新版本可以在組織內部和外部的任何地方保護文件。FinalCode 具有安全性和可用性功能。重點包括保護整個文件夾的能力,新的FinalCode資源管理器,在打開文件/文件夾時對用戶進行身份驗證的能力,對複雜應用程式和Adobe Illustrator等設計軟體的增強支持以及為搜索目的標記安全文件的功能。
FinalCode提供強大的加密和廣泛的使用控制,包括即使在共享文件後也能遠程刪除文件。FinalCode對文件進行加密,並允許用戶選擇他們想要實施的控件,並提供完整的文件保護,以防止針對性攻擊,疏忽和內部欺詐。它可以輕鬆地與公司現有的文件管理和雲端協作基礎架構集成,並可根據項目,部門和業務應用程式需求進行部署。
安全容器 - 安全容器功能加密整個文件夾而不是單獨加密文件。這樣,用戶可以同時打開安全容器中的多個安全文件,
而無需逐個打開和關閉文件的麻煩
對複雜應用程序的擴展支持 - 支持AutoCAD,Photoshop和Illustrator等設計軟體,允許用戶同時在安全容器中查看多個設計
FinalCode Explorer - 與標準Windows資源管理器類似,FinalCode Explorer允許用戶在簡化的可搜索界面中
輕鬆組織FinalCode安全文件
打開時身份驗證 -強身份驗證功能允許用戶在每次打開安全文件或文件夾時設置身份驗證。當需要高度安全的身份驗證時,
以及多個用戶可以訪問共享系統時,此功能非常有用
標記 - 用戶現在可以通過文件的元數據將標記添加到其安全文件中。以前,文件搜索僅可通過訪問日誌獲得。
標籤允許用戶以更簡單的方式查找文件
支持Zip文件 - 以前,用戶必須首先解壓縮文件,然後添加修改並再次壓縮文件。使用5.3中的安全容器功能,用戶可以通過
FinalCode Explorer直接編輯和保存文件,而無需解壓縮和重新壓縮
Ver.5和Ver.6之間的區別
FinalCode Ver.5
FinalCode Ver.6
Billable
Within companies and organizations user *1 of encryption, editing, and viewing user
Companies and organizations within the user *1 of encryption and editing user
(in-house viewing user is free of charge)
(Users outside the company/group *2 are free)
Fee structure according to the number of purchased licenses
Not applicable
Yes
Deletion / illegal notification function
Paid option
Free
(license / year)
(provided as a standard function)
Network Folder Security
Paid option
Free
(license / year)
(provided as a standard function)
Transparent Secure function
None
Yes
*1 A user whose e-mail address has the "company domain registered by the main administrator on the management screen".
*2 Users with e-mai...