tag:blogger.com,1999:blog-1746946614390371171.post4192520801463839726..comments2023-05-09T02:31:13.939-07:00Comments on Computer Forensics, Malware Analysis & Digital Investigations: EnCase + F-Response + EnScript = very affordable network forensics & eDiscoveryLance Muellerhttp://www.blogger.com/profile/15789264000499223230noreply@blogger.comBlogger9125tag:blogger.com,1999:blog-1746946614390371171.post-90419101578996569102010-03-18T08:57:05.630-07:002010-03-18T08:57:05.630-07:00Anonymous, thank you, I fixed the initial link tha...Anonymous, thank you, I fixed the initial link that was broken.Lance Muellerhttps://www.blogger.com/profile/15789264000499223230noreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-86386087395507553052010-03-18T08:44:53.842-07:002010-03-18T08:44:53.842-07:00F-response is not correctly linked to the site.F-response is not correctly linked to the site.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-68310788674316405382010-03-17T09:37:51.712-07:002010-03-17T09:37:51.712-07:00Thanks for the feedback, Lance.
I'm familiar...Thanks for the feedback, Lance. <br /><br />I'm familiar with the FIM and have a copy. I was wondering what other capabilities I may be missing compared to the EnCase Forensics & F-Response combo you described. Now I know...<br /><br />Best regards, PhilPhil Rodokanakishttps://www.blogger.com/profile/17663314202364550318noreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-92027100688893881742010-03-17T05:11:46.029-07:002010-03-17T05:11:46.029-07:00Phil, EnCase FIM is the EnCase you already know wi...Phil, EnCase FIM is the EnCase you already know with network capabilities. <br /><br />The only Additional feature you get from FIM or EnCase Enterprise is snapshot ability, which gives you running processes, etc which is very helpful when doing incident response.<br /><br />But then on the other hand F-Response handles network connection to Windows, Linux, Apple, Solaris, AIX, SCO, HPUX, and Freebsd. FIM does not support all those platforms.<br /><br />Everything else that you could do or want to do with FIM, can be done with EnCase forensic.<br /><br />If you are not familiar with EnCase FIM, it looks, tastes, smells and acts just like the EnCase Forensic version you use now, just with the ability to reach out and connect to a remote machine. The analysis part ids the same in EnCase Forensic and FIM.Lance Muellerhttps://www.blogger.com/profile/15789264000499223230noreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-91713131770244039882010-03-16T17:50:42.604-07:002010-03-16T17:50:42.604-07:00Thanks for the feedback, Lance.
My question wasn...Thanks for the feedback, Lance. <br /><br />My question wasn't well articulated. What I was trying to ask was whether the combination of EnCase Forensic and F-Response had more to offer that EnCase FIM. From what you're saying, I gather that one of the differences would be in the FIM's limitation over concurrent connections.Phil Rodokanakishttps://www.blogger.com/profile/17663314202364550318noreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-80556535242081284042010-03-13T02:30:45.637-08:002010-03-13T02:30:45.637-08:00Phil, I assume you own at least EnCase Forensic ed...Phil, I assume you own at least EnCase Forensic edition, if so then you only need to buy F-Response Enterprise. If you already own a lessor version, then you only need to upgrade that. The $8,000 was if you own nothing.<br /><br />F-Repsonse does not offer any features like FIM, its not a forensic analysis tool, its a network connection tool. The analysis and features are coming from EnCase, so whatever you have in your EnCase Forensic version as far as modules, or EnScripts, you can use them like usual.<br /><br />FIM has limitations on concurrent connections, And you will pay more for more connections with FIM, F-Response does not.<br /><br />I am not preaching that F-Response is a better solution to FIM or EnCase Enterprise. I am just sharing an alternative affordable solution. We all have our favorites and each tool has it's own strength and weaknesses. As I mentioned, I love EnCase Enterprise and FIM, but I cant afford that or the licensing (only installed on one machine), whereas this solution can be installed on any machine. The post above is meant to describe just another alternative solution.Lance Muellerhttps://www.blogger.com/profile/15789264000499223230noreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-44820329784213083242010-03-12T17:32:13.880-08:002010-03-12T17:32:13.880-08:00Lance, if it costs around $9K, wouldn't one be...Lance, if it costs around $9K, wouldn't one be better off with EnCase FIM instead? I know it's advertised a lot higher, but they discount it from time to time. And FIM comes with the EnCase Consultants edition which includes all the plug-ins. Does F-Response offer any additional features not found in the FIM?Phil Rodokanakishttps://www.blogger.com/profile/17663314202364550318noreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-84026384227125262482010-03-11T18:36:53.565-08:002010-03-11T18:36:53.565-08:00Raffael Vargas
Great Lance ....Raffael Vargas<br />Great Lance ....Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-1746946614390371171.post-55221202930566823542010-03-11T10:08:14.630-08:002010-03-11T10:08:14.630-08:00Very cool, Lance, thanks.
I'm curious though -...Very cool, Lance, thanks.<br />I'm curious though - does this contravene the EnCase Forensic EULA?Anonymousnoreply@blogger.com