Computer Forensic Tool: Encase Forensic
EnCase Forensic is the industry standard in computer forensic investigation technology. With an intuitive GUI, superior analytics, enhanced email/Internet support and a powerful scripting engine, EnCase provides investigators with a single tool, capable of conducting large-scale and complex investigations from beginning to end. Law enforcement officers, government/corporate investigators and consultants around the world benefit from the power of EnCase Forensic in a way that far exceeds any other forensic solution.
-Acquire data in a forensically sound manner using software with an unparalleled record in courts worldwide.
-Investigate and analyze multiple platforms — Windows, Linux, AIX, OS X, Solaris and more — using a single tool.
-Save days, if not weeks, of analysis time by automating complex and routine tasks with prebuilt EnScript® modules, such as Initialized Case and Event Log analysis.
-Find information despite efforts to hide, cloak or delete.
-Easily manage large volumes of computer evidence, viewing all relevant files, including “deleted” files, file slack and unallocated space.
-Transfer evidence files directly to law enforcement or legal representatives as necessary.
-Review options allow non-investigators, such as attorneys, to review evidence with ease.
-Reporting options enable quick report preparation.

MacLockPick™ is a valuable tool for law enforcement professionals to perform live forensics on Mac OS X systems. The solution is based on a USB Flash drive that can be inserted into a suspect’s Mac OS X computer that is running (or sleeping). Once the software is run it will extract data from the Apple Keychain and system settings in order to provide the examiner fast access to the suspect’s critical information with as little interaction or trace as possible. And also this is the only professional tool which can be use to extract the extensive encrypt information under the close-down condition of computer.