<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post4192520801463839726..comments</id><updated>2010-03-18T08:57:05.635-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: EnCase + F-Response + EnScript = very affordable n...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/4192520801463839726/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9041910157899656910</id><published>2010-03-18T08:57:05.630-07:00</published><updated>2010-03-18T08:57:05.630-07:00</updated><title type='text'>Anonymous, thank you, I fixed the initial link tha...</title><content type='html'>Anonymous, thank you, I fixed the initial link that was broken.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/9041910157899656910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/9041910157899656910'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268927825630#c9041910157899656910' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8638608739550755305</id><published>2010-03-18T08:44:53.842-07:00</published><updated>2010-03-18T08:44:53.842-07:00</updated><title type='text'>F-response is not correctly linked to the site.</title><content type='html'>F-response is not correctly linked to the site.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/8638608739550755305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/8638608739550755305'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268927093842#c8638608739550755305' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1331438067'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6831078867431640538</id><published>2010-03-17T09:37:51.712-07:00</published><updated>2010-03-17T09:37:51.712-07:00</updated><title type='text'>Thanks for the feedback, Lance. 

I&amp;#39;m familiar...</title><content type='html'>Thanks for the feedback, Lance. &lt;br /&gt;&lt;br /&gt;I&amp;#39;m familiar with the FIM and have a copy. I was wondering what other capabilities I may be missing compared to the EnCase Forensics &amp;amp; F-Response combo you described. Now I know...&lt;br /&gt;&lt;br /&gt;Best regards, Phil</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/6831078867431640538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/6831078867431640538'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268843871712#c6831078867431640538' title=''/><author><name>Phil Rodokanakis</name><uri>http://www.blogger.com/profile/17663314202364550318</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://philr.us/images/PhilR_2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1449037696'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9202710068889388174</id><published>2010-03-17T05:11:46.029-07:00</published><updated>2010-03-17T05:11:46.029-07:00</updated><title type='text'>Phil, EnCase FIM is the EnCase you already know wi...</title><content type='html'>Phil, EnCase FIM is the EnCase you already know with network capabilities. &lt;br /&gt;&lt;br /&gt;The only Additional feature you get from FIM or EnCase Enterprise is snapshot ability, which gives you running processes, etc which is very helpful when doing incident response.&lt;br /&gt;&lt;br /&gt;But then on the other hand F-Response handles network connection to Windows, Linux, Apple, Solaris, AIX, SCO, HPUX, and Freebsd. FIM does not support all those platforms.&lt;br /&gt;&lt;br /&gt;Everything else that you could do or want to do with FIM, can be done with EnCase forensic.&lt;br /&gt;&lt;br /&gt;If you are not familiar with EnCase FIM, it looks, tastes, smells and acts just like the EnCase Forensic version you use now, just with the ability to reach out and connect to a remote machine. The analysis part ids the same in EnCase Forensic and FIM.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/9202710068889388174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/9202710068889388174'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268827906029#c9202710068889388174' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9171313177024403988</id><published>2010-03-16T17:50:42.604-07:00</published><updated>2010-03-16T17:50:42.604-07:00</updated><title type='text'>Thanks for the feedback, Lance. 

My question wasn...</title><content type='html'>Thanks for the feedback, Lance. &lt;br /&gt;&lt;br /&gt;My question wasn&amp;#39;t well articulated. What I was trying to ask was whether the combination of EnCase Forensic and F-Response had more to offer that EnCase FIM. From what you&amp;#39;re saying, I gather that one of the differences would be in the FIM&amp;#39;s limitation over concurrent connections.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/9171313177024403988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/9171313177024403988'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268787042604#c9171313177024403988' title=''/><author><name>Phil Rodokanakis</name><uri>http://www.blogger.com/profile/17663314202364550318</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://philr.us/images/PhilR_2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1449037696'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8055653524208128404</id><published>2010-03-13T02:30:45.637-08:00</published><updated>2010-03-13T02:30:45.637-08:00</updated><title type='text'>Phil, I assume you own at least EnCase Forensic ed...</title><content type='html'>Phil, I assume you own at least EnCase Forensic edition, if so then you only need to buy F-Response Enterprise. If you already own a lessor version, then you only need to upgrade that. The $8,000 was if you own nothing.&lt;br /&gt;&lt;br /&gt;F-Repsonse does not offer any features like FIM, its not a forensic analysis tool, its a network connection tool. The analysis and features are coming from EnCase, so whatever you have in your EnCase Forensic version as far as modules, or EnScripts, you can use them like usual.&lt;br /&gt;&lt;br /&gt;FIM has limitations on concurrent connections, And you will pay more for more connections with FIM, F-Response does not.&lt;br /&gt;&lt;br /&gt;I am not preaching that F-Response is a better solution to FIM or EnCase Enterprise. I am just sharing an alternative affordable solution. We all have our favorites and each tool has it&amp;#39;s own strength and weaknesses. As I mentioned, I love EnCase Enterprise and FIM, but I cant afford that or the licensing (only installed on one machine), whereas this solution can be installed on any machine. The post above is meant to describe just another alternative solution.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/8055653524208128404'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/8055653524208128404'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268476245637#c8055653524208128404' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4482032978421308324</id><published>2010-03-12T17:32:13.880-08:00</published><updated>2010-03-12T17:32:13.880-08:00</updated><title type='text'>Lance, if it costs around $9K, wouldn&amp;#39;t one be...</title><content type='html'>Lance, if it costs around $9K, wouldn&amp;#39;t one be better off with EnCase FIM instead? I know it&amp;#39;s advertised a lot higher, but they discount it from time to time. And FIM comes with the EnCase Consultants edition which includes all the plug-ins. Does F-Response offer any additional features not found in the FIM?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/4482032978421308324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/4482032978421308324'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268443933880#c4482032978421308324' title=''/><author><name>Phil Rodokanakis</name><uri>http://www.blogger.com/profile/17663314202364550318</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://philr.us/images/PhilR_2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1449037696'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8402638422712526248</id><published>2010-03-11T18:36:53.565-08:00</published><updated>2010-03-11T18:36:53.565-08:00</updated><title type='text'>Raffael Vargas
Great Lance ....</title><content type='html'>Raffael Vargas&lt;br /&gt;Great Lance ....</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/8402638422712526248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/8402638422712526248'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268361413565#c8402638422712526248' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-656715464'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5522120293056682354</id><published>2010-03-11T10:08:14.630-08:00</published><updated>2010-03-11T10:08:14.630-08:00</updated><title type='text'>Very cool, Lance, thanks.
I&amp;#39;m curious though -...</title><content type='html'>Very cool, Lance, thanks.&lt;br /&gt;I&amp;#39;m curious though - does this contravene the EnCase Forensic EULA?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/5522120293056682354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/4192520801463839726/comments/default/5522120293056682354'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html?showComment=1268330894630#c5522120293056682354' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/03/encase-f-response-enscript-very.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-4192520801463839726' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/4192520801463839726' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1822818916'/></entry></feed>
