enterprisesecuritymag

Enterprise Security Magazine

OpenText
The One Stop-Shop for Digital Forensics

Mark J. Barrenechea, Vice Chairman, CEO & CTO, OpenTextMark J. Barrenechea, Vice Chairman, CEO & CTO
Unbridled access to the digital world, dependence on and generation of data, and the emergence of sophisticated IT infrastructures have brought information security and integrity at stake. As a result, the regulatory landscape continues to evolve and become more stringent. And given the rate at with enterprise technologies advance, adhering to mandates such as GDPR is a complicated affair. On the other hand, given today’s cyber-threat landscape, the need for tools that can proactively protect and keep watch on assets, including personnel and endpoints, is equally crucial. In such a scenario, traditional data loss prevention solutions (DLP) cannot keep up owing to their inability of accessing data on endpoints, working on historical data intelligence, and providing the highest level of insight into information by automatically categorizing private and sensitive data. Adding to this, such solutions often fail to go beyond the on-premise repositories through the seamless integration with a cloud-based platform. With a thorough understanding of these pain points, OpenText, the Waterloo-based firm, with its state-of-the-art solutions enables enterprises to deal with regulatory frameworks by ensuring proper forensics through the identification and classification of threats and empowers them to undertake appropriate remedial measures. “Recent, high-profile data breaches show that security and data privacy must be at the top of the priority list for the intelligent and connected enterprise. Information powers the world, and technologies like artificial intelligence (AI), the Internet of Things (IoT) and hyper-connectivity are transforming business on a planetary scale. At the same time, cybercrime and cyberwarfare are being redefined. Now, more than ever, organizations require the latest information security platforms to collect, analyze, and remediate urgent threats – real time,” says Mark J. Barrenechea, vice chair, CEO, and CTO of OpenText.

Another key area where OpenText’s digital forensic investigation solutions focus is the realm of criminality. With the aggrandizement of technology, complexities of the criminal activities have grown exponentially, and it has become imperative for the investigating agencies to trace the digital footprints of criminals in a streamlined way. To this end, OpenText’s EnCase, a trailblazing solution in the field of computer forensics, enables investigators to accumulate data across a wide variety of devices to ensure proper investigation and generate sound and apt reports keeping the evidence integrity intact. Before delving deeper into the details of the solution, some pages from the history books need be turned over. The story dates back to the February of 2005 when a 1.44-megabyte floppy disk along with a letter, a gold-colored necklace, and a photocopy of John Sandford’s celebrated novel Rules of Prey’s cover reached KSAS-TV in Wichita. The incident was sensational since it was possibly a “gift” from the infamous BTK killer and could be an important missing link to the mystery which began in the January of 1974 with the killing of four members of the Otero family followed by six more murders. Ultimately, the floppy became instrumental in unraveling the mystery when the forensic experts used the Encase Forensic software to extract a deleted Microsoft Word document from it and analyze its metadata. Ultimately, the investigating officers successfully traced Dennis Rader, the BTK man who remained behind the veil for years.


EnCase enables investigators to accumulate data across a wide variety of devices to ensure proper investigation


A Confluence and a Journey toward the Acme

With its Discovery suite, for a long time, OpenText has remained a front runner in the space of enterprise content management (ECM). To fulfill the long-cherished desire of steering their offering to new heights, in 2017, OpenText acquired Guidance Software. Through this merger, Guidance’s EnCase, the industry-leading digital investigation, forensic security, and data risk management solution became instrumental in broadening the Discovery portfolio. The integration between the top-notch enterprise information management solutions (EIM) and forensic security technologies enabled OpenText to expand their offering’s capabilities, and ultimately, establish a presence in diverse industry verticals including highly regulated and litigious sectors such as government, federal agencies, banking, and insurance.

Key Capabilities

For over two decades, with three significant parts, EnCase Forensic, EnCase Endpoint Investigator, and EnCase Mobile Investigator, the forensic investigative solutions has been pioneering in the digital investigation sphere by both ensuring law enforcement and cybersecurity.

The OpenText EnCase Forensic is designed to empower examiners to decrypt evidence from a large number of devices with unmatched precision and includes a lot of features for in-depth forensic analysis. Besides enabling investigators to operate with speed, this solution offers customizable templates to build easy to read professional reports. It’s scalable and allows them to recover a deleted or modified file by examining Volume Shadow Snapshot (VSS). Moving ahead from there, the latest EnCase Forensic version 8.08 drives digital investigations to a new height leveraging new evidence decryption abilities from Symantec endpoint encryption, Apple file system, and Dell full disk encryption. With this new version, users can have access to evidence from both online and on-premises services. In addition, mobile acquisition and an easy-to-use interface will ensure elevated user experience.

The next important aspect of its forensic solutions is OpenText EnCase Endpoint Investigator, a cutting-edge solution for corporate houses and government agencies to render discreet internal investigations without hampering everyday operations. With the enormous change in the risk landscape, it has become essential to organizations to peep into employee activities for dealing with several issues such as compliance violations, IT policy violations, IP theft, or regulatory inquiries. The EnCase Endpoint Investigator is a cost-effective and proven tool to empower the investigators to seamlessly search and collect data from the endpoints irrespective of the location of an employee. Interestingly, it allows examiners to work on a diverse range of operating systems including Microsoft Windows, Linux, Apple Mac, or Unix and the analysis of critical data such as email, text messages, or browser artifacts can be stored into EnCase Evidence File format which is accepted in courts across the globe.

Allowing investigators to access laptops, computers remotely, or servers, EnCase Endpoint Investigator mitigates several risk factors and keeps an organization steady before any kind of regulation. The introduction of its new version (8.08), has initiated significant changes through new encryptions and data acquisition capabilities from both on-premises and cloud repositories.

To comprehend diverse risk factors in entirety, an organization needs to undertake a plethora of approaches such as sandboxing, malware analysis, or user behavior analytics. Therefore, OpenText offers an add-on, OpenText EnCase Advanced Detection to EnCase Endpoint Security to enhance its ability to detect and respond to an issue. Most importantly, besides mere threat intelligence, it can find polymorphic malware by leveraging machine learning, partial hashing, or PE header analysis, and empowers teams to differentiate common adware and commodity malware from active breaches. Furthermore, this agentless and cloud-based security technology facilitates complex digital forensics and incident response (DFIR) investigations.

Going above and beyond to meet the diverse demands of clients and licensing them to stay ahead of the curve, OpenText has brought a comprehensive mobile forensics solution, EnCase Mobile Investigator to change the way investigators deal with critical mobile device evidence including text messages, call records, and application data.

With the growing number of smartphone owners, a mobile device has turned into a vital witness to reveal a case and leveraging EnCase Mobile Investigator examiners can have unparalleled access to mobile devices through built-in bypass function to trace a wide range of evidence. The Mobile Investigator empowers examiners to use Optical Character Recognition (OCR) for finding, extracting, and analyzing data from graphic files such as PDFs and photos. Interestingly, based on permissions, this solution can accumulate information from social networking applications, and cloud data sources such as Google Drive attached to a mobile device and at the end of the day, investigators can create a report in a simplified way including HTML, Timeline, or PDF.

"Now, more than ever, organizations require the latest information security platforms to collect, analyze, and remediate urgent threats – real time"

From the Horse’s Mouth

With such a unique approach, OpenText has added several big names to its client list; hence, the compelling story of a customer, Lennar Corporation, a construction, and real estate company, based out of Miami, can best validate the unique value proposition of its offerings. Joshua Marlin, Manager of Security Operations of the company, believes EnCase enabled his team to perform three critical tasks including forensics, e-discovery, and cybersecurity to any remote machine and made them better at their job by automating processes and bringing flexibility. Eventually, it enabled the organization to stay sharp before litigations.

With such legacy spanning intriguing customer success stories, robust offering, and strategic acquisition, it is evident that OpenText has carved its niche in a competitive market and is spearing ahead vehemently.

- Russell Thomas
    July 12, 2019

Company
OpenText

Headquarters
Waterloo, Canada

Management
Mark J. Barrenechea, Vice Chairman, CEO & CTO

Description
Having acquaintance of the hurdles that come before the investigators, the forensic solution from OpenText, OpenText EnCase Forensic is designed to empower examiners to decrypt evidence from a large number of devices with unmatched precision and includes a lot of features for in-depth forensic analysis. Besides enabling investigators to operate with speed, this solution offers customizable templates to build easy to read professional reports. It also provides extensibility and allows investigators to recover a deleted or modified file by examining Volume Shadow Snapshot (VSS)

© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.