Digital Forensics and Incident Response

OpenText Forensic (EnCase)

Gather digital forensic evidence reliably, defensibly, and efficiently

A desktop computer showing OpenText Forensic UI

Streamline digital forensic investigations

Digital evidence has become the most crucial—and potentially overwhelming—element of modern investigations. Investigators must gather massive amounts of data from a huge array of devices, in a variety of formats, all while preserving its integrity.

Solving digital forensic investigation challenges

OpenText™ Forensic (Encase) is industry-leading digital forensic investigation software that enables law enforcement, government agencies, and enterprises to collect, triage, analyze, and report on digital evidence. With AI-powered automation, artifact-first workflows, and support for 36,000+ devices and cloud sources, OpenText Forensic helps examiners close digital forensic investigation cases faster while maintaining evidential integrity.

Why OpenText Forensic?

Rely on digital forensic investigation software trusted by courts and investigators for over 20 years.

  • 75%
    faster time to evidence
    Process digital forensic evidence up to 75 percent faster than competing digital forensic investigation tools—tested with real-world data.
    Learn more
  • 36,000
    source profiles supported
    Supports 36,000+ device profiles, cloud apps, and file systems to uncover hidden digital forensic evidence.
  • Court-proven
    trusted evidence integrity
    Deliver digital forensic evidence in a court-accepted format, proven in legal proceedings worldwide.

Use cases

Support digital forensic examiners, investigators, and legal teams with use cases like evidence acquisition, triage, AI-assisted review, and court-ready reporting to uncover, analyze, and present digital evidence quickly and reliably.

  • Collect digital forensic evidence from Windows®, Mac®, Linux®, mobile devices, and cloud platforms like Microsoft® 365 and Facebook® using powerful forensic tools.

  • Identify key artifacts first using customizable workflows that streamline the analysis of digital evidence in real time.

  • Use AI in your digital forensics software to detect images of interest—including CSAM and weapons—and reduce manual review time.

  • Create customizable reports that present complex findings clearly and are trusted by digital forensic investigators, attorneys, and judges.

    Key features

    OpenText Forensic examines, categorizes, and reports digital evidence while accelerating the speed, accuracy, and integrity of your digital forensic investigation.

    ""

    Artifact-first workflow

    Prioritizes critical evidence from the start to streamline digital forensic investigations and close cases faster with fewer resources.

    ""

    Multi-source device compatibility

    Collects and analyzes data from over 36,000 devices—including PCs, smartphones, tablets, and cloud platforms—to provide a complete digital forensic investigation picture.

    ""

    AI-powered image classification

    Flags sensitive content like—weapons and CSAM—automatically to reduce manual review and accelerate digital forensic investigation results.

    ""

    Flexible reporting tools

    Builds polished, court-ready reports using customizable templates to meet the needs of legal and digital forensic investigation teams.

    ""

    Court-admissible evidence format

    Presents digital forensic evidence in a format trusted and validated by courts, ensuring digital evidence integrity.

    ""

    Encrypted file system acquisition

    Extracts encrypted data from systems like BitLocker® and FileVault to preserve digital forensic evidence others miss.

    ""

    Workflow and review automation

    Automates repetitive digital forensic investigation tasks and streamlines evidence review with EnScripts and guided workflows.

    ""

    Volume shadow copy analysis

    Recovers deleted or historical files during the digital forensic investigation process using built-in support for Windows Volume Shadow Copies.

    How to buy

    OpenText Forensic

    Allows investigators to identify the most important pieces of evidence, prioritize those pieces, process them and analyze data for evidence of wrong doing.

    Comprehensive artifact support Information icon
    Artificial Intelligence & Machine Learning Information icon

    Enables investigators to locate evidence on an ever-increasing variety of devices and locations within those devices.

    Extensive device support Information icon
    Optical character recognition Information icon
    AFF4 evidence format Information icon
    IPv6 support for Linux systems Information icon
    Support of mobile artifacts Information icon

    Improves the efficiency and effectiveness of overburdened investigation teams to help them get to the truth faster.

    Advanced indexing engine Information icon
    Artifact-based workflows Information icon
    International language support Information icon
    Timeline view Information icon
    Add On
    OpenText Mobile InvestigatorInformation icon
    Add On
    OpenText Forensics TX1 ImagerInformation icon
    Add On
    OpenText Forensics TD4 DuplicatorInformation icon
    Add On
    OpenText Forensics BridgeInformation icon

    Off cloud Information icon
    Private cloud Information icon

    Accelerate the value of OpenText Forensic

    Deployment

    OpenText offers a flexible deployment option for OpenText Forensic.

    Add-ons

    Extend the capabilities of your digital forensic investigations with additional digital forensic and incident response capabilities.

    Professional Services

    OpenText Professional Services combines end-to-end solution implementation with comprehensive technology services to help improve systems.

    Partners

    OpenText helps customers find the right solution, the right support, and the right outcome.

    Training

    OpenText Learning Services offers comprehensive enablement and learning programs to accelerate knowledge and skills.

    Communities

    Explore our OpenText communities. Connect with individuals and companies to get insight and support. Get involved in the discussion.

    Premium Support

    Optimize the value of your OpenText solution with dedicated experts who provide mission-critical support for your complex IT environment.

    OpenText Forensic resources

    DataExpert logo

    Information security firm helps law enforcement analyze digital evidence

    Learn more
    Southern Alberta Internet Child Exploitation Unit logo

    Alberta law enforcement unit significantly improves case efficiency

    Learn more
    Play video

    The changing face of digital forensics

    Watch the video
    Play video

    Fireside chat on the role of forensics with Microsoft

    Watch the video
    Play video

    Collections from Microsoft Teams

    Watch the video
    • OpenText Forensic can collect data from a wide variety of sources including hard drives, SSDs, removable media, memory (RAM), mobile phones, and IoT devices. It can recover deleted files, parse file systems, extract artifacts (like browser history or email), and collect system metadata.

    • OpenText Forensic is widely recognized in the digital forensics community for its robust capabilities in evidence recovery, artifact analysis, and court-admissible reporting. Its comprehensive support for diverse file systems and platforms makes it a preferred choice for forensic examiners.

    • Unlike many digital forensic investigation tools, OpenText Forensic offers deep-dive analysis capabilities, customizable processing options, and integration with other forensic suites. Its reliability, scalability, and court-proven methodologies set it apart from competitors.

    • Yes. While it offers advanced tools for seasoned examiners, OpenText Forensic also includes guided workflows and intuitive interfaces, making it accessible to broader teams involved in digital forensic investigations.

    • Yes. OpenText Forensic integrates digital forensic artifacts from over 36,000 different mobile device profiles, enabling investigators to include mobile data in their digital forensic investigations, alongside traditional endpoint and storage media.

    • OpenText offers certified training programs to help users maximize the platform's capabilities in digital forensic investigations, ranging from beginner courses to advanced forensic analysis techniques.

      ""
      March 31, 2025

      The growing role of mobile data in digital forensics

      investigators need tools to unlock and analyze evidence from mobile devices.

      Read the blog
      ""
      April 15, 2024

      Transforming digital forensic investigations

      Investigators must navigate many challenges stemming from the exponential growth of digital data.

      Read the blog

      Take the next step

      Explore how this digital forensic investigation software can streamline your evidence collection & analysis workflows. Speak with an expert to see why OpenText is the go-to solution.

      Contact us