- Spotting compromised admin accounts ( link): By analyzing the activity of end users logged in with administrator credentials, the interface shows activity across multiple domains by the same administrator account. Such activity points to the credentials having been compromised, which could lead to data theft or worse.
- Pointing to advanced persistent threats (APTs) ( link): While many security solutions highlight network traffic to countries where suspected hacking originates, EnCase Analytics lets the security administrator quickly see which processes and services are making requests to those countries. If a kernel service is connecting to one of these countries, this may be a serious problem and potential evidence of an APT attack.
- Visualizing polymorphic malware ( link): Few security solutions can spot malware that changes its name to avoid signature detection. EnCase Analytics shows the number of instances of a process and that number’s deviation from normal, as well as other processes that might have the same prevalence over a period of time. If there are similarities in the way multiple processes are acting across machines, it is clear, visual evidence of polymorphic malware.
Availability and PricingEnCase Analytics is available through the Guidance Software channel partner network and directly from Guidance Software. For a limited time, Guidance Software is offering attractive introductory pricing. Through the end of the year, customers that buy both EnCase Analytics and EnCase® Cybersecurity—a solution that facilitates real-time and on-demand incident response, as well as sensitive data discovery—receive one of the solutions at no additional cost. Special terms and conditions apply. Please contact Guidance Software for more details. About EnCase Analytics EnCase Analytics is the security intelligence product designed to derive insights from the data generated by endpoint activity. Instead of trusting a potentially compromised operating system, EnCase Analytics leverages kernel-level access for endpoint data collection—providing a repository of the most reliable data for insights into undetected risks and threats. It also enables users to quickly visualize endpoint data from multiple dimensions, regardless of how large or disparate the data sets may be. Through its interactive visual interface, EnCase Analytics exposes suspicious patterns, commonalities, and anomalies, allowing for on-the-fly adjustments to zero-in on the threats. About Guidance Software, Inc. Guidance Software is recognized worldwide as the industry leader in digital investigative solutions. Its EnCase® Enterprise platform is used by numerous government agencies, more than 65 percent of the Fortune 100, and more than 40 percent of the Fortune 500, to conduct digital investigations of servers, laptops, desktops and mobile devices. Built on the EnCase Enterprise platform are market-leading electronic discovery and cyber security solutions, EnCase eDiscovery, EnCase Cybersecurity, and EnCase Analytics. They empower organizations to respond to litigation discovery requests, perform sensitive data discovery for compliance purposes, conduct speedy and thorough security incident response, and reveal previously hidden advanced persistent threats or malicious insider activity. For more information about Guidance Software, visit www.encase.com. EnCase®, EnScript®, FastBloc®, EnCE®, EnCEP®, Guidance Software™ and Tableau™ are registered trademarks or trademarks owned by Guidance Software in the United States and other jurisdictions and may not be used without prior written permission. All other trademarks and copyrights referenced in this press release are the property of their respective owners.