Thursday, December 3, 2009

Encase and Windows 7, Server 2008

The Remote Desktop Protocol and Encase Forensic do not play well together in Windows 7 and Server 2008.

The traditional fix to this in XP and Server 2003 was to use the MSTSC command with a /console flag (or /admin for later service packs) to carry out console mode. However this does not work anymore. So I did a little research...

It's stated on Guidance's website that  "EnCase is not officially supported running over Remote Desktop due to the manner in which the Remote Login Account is given access to the System devices". A discussion with one of their support representatives and some messages on their forum in fact further confirmed that Encase has never supported RDP (in any of their releases).

BUT, Guidance then goes to say in the same article that "IF the RDP configuration does not work the only alternative is to purchase the SAFE NAS (Network Authentication Server) to license EnCase over the network." Well, if that's not a contradicting statement, I don't know what is! So they are saying its not supported but if you want to make it work you can BUY something they sell to make it work? As a user this makes me shake my head and as a shareholder, I would be lying if I said I wasen't smiling :-) 

Some say this is a licensing strategy, a method to prevent multiple users from using multiple instances of encase off of one license. But I don't see how that type of "abuse" is even technically possible under the current limitation of RDP and Encase only working in console mode. So I don't buy that really. I think the reason it does not work in Windows 7 and 2008 server is because of something that has changed in the O/S. I'm not sure what this is but I'm going to look into it.

So here's a solution I purpose to Guidance. Migrate over to a system like Access Data's License Manager and Code Meter dongle (hold on, did I just say something good about AD?). With Access Data's License Manager system a user has the ability to transfer/update licenses from and to their dongles. Ideally, one could use a dongle normally and then if one wanted to use RDP, they could migrate their license over from the dongle to the NAS Safe. Then vice versa. Damn I think that is genius! LOL But this would sure make people happy!

Well enough of that, here's something good. I have 2 round about workarounds for Win 7 and 2008 Server to get RDP working -

  1. Disable Fast User Switching, Disable User Account Controls, start up your instance of Encase Forensic, open your case up/start your processing. THEN, remote in using the "mstsc /admin" command and log in as the same user you have an instance of Encase already running under. This works.
  2. Now, you can always use a VNC or PCAnywhere application to accomplish this as well. Works like a charm.
But neither of these are practical solutions. Welp, back to XP for me!

Dav Nads

- Posted using BlogPress from my iPhone


  1. Some things you may not know about this situation:

    The same applies to Vista.

    If you do have a NAS, you cannot launch EnCase via RDP on the system that has the dongle connected.

    Guidance only staffs the NAS setup function during office hours, so if something goes wrong after hours, it stays wrong for several hours (if not the entire weekend).

  2. hi,You have a very good blog that the main thing a lot of interesting and useful! thanx. usb protection

  3. I've been running into this issue, which is maddening, if I want to work away from the office. Strangely enough, my co-worker can sustain the "enterprise" status as long as he launches EnCase locally, while mine terminates the enterprise status and downgrades to "aquisition" mode as soon as I RDP in. Since our environment does not allow direct calls to MSTSC while using VPN (the service calls it behind the scenes) I would have to use a messy jump-box set-up. We have the NAS dongle set-up, too, but in order to use it I would need a full tunnel AND I believe run EnCase on my remote machine rather than the one on my network. This setup does work, however given the speed issues outside of the core net, it is not tenable. I have to imagine that there has to be some way to change the behavior of Windows, assuming the modification is not at the kernel level. If I had to put some money down on the perp, I'd say it's probably related to UAC, the most significant change to OSs since XP. If anyone stumbles across other work-arounds, I'd love to hear about them.

    1. "Windows Server 2008 provides a solid foundation for all of your server workload and application requirements while being easy to deploy and manage."
      Windows Server 2008 Support

  4. This bug annoyed me a lot.

    A workaround is to enable automatic login, and then add encase to the Startup folder on the Start menu.

    You can then connect via RDP, and EnCase will already be running.

    If it crashes, you're out of luck and will have to run shutdown -r.

    Work from home theory is fast gaining popularity because of the freedom and flexibility that comes with it. Since one is not bound by fixed working hours, they can schedule their work at the time when they feel most productive and convenient to them. Women & Men benefit a lot from this concept of work since they can balance their home and work perfectly. People mostly find that in this situation, their productivity is higher and stress levels lower. Those who like isolation and a tranquil work environment also tend to prefer this way of working. Today, with the kind of communication networks available, millions of people worldwide are considering this option.

    Women & Men who want to be independent but cannot afford to leave their responsibilities at home aside will benefit a lot from this concept of work. It makes it easier to maintain a healthy balance between home and work. The family doesn't get neglected and you can get your work done too. You can thus effectively juggle home responsibilities with your career. Working from home is definitely a viable option but it also needs a lot of hard work and discipline. You have to make a time schedule for yourself and stick to it. There will be a time frame of course for any job you take up and you have to fulfill that project within that time frame.

    There are many things that can be done working from home. A few of them is listed below that will give you a general idea about the benefits of this concept.

    This is the most common and highly preferred job that Women & Men like doing. Since in today's competitive world both the parents have to work they need a secure place to leave behind their children who will take care of them and parents can also relax without being worried all the time. In this job you don't require any degree or qualifications. You only have to know how to take care of children. Parents are happy to pay handsome salary and you can also earn a lot without putting too much of an effort.

    For those who have a garden or an open space at your disposal and are also interested in gardening can go for this method of earning money. If given proper time and efforts nursery business can flourish very well and you will earn handsomely. But just as all jobs establishing it will be a bit difficult but the end results are outstanding.

    Freelance can be in different wings. Either you can be a freelance reporter or a freelance photographer. You can also do designing or be in the advertising field doing project on your own. Being independent and working independently will depend on your field of work and the availability of its worth in the market. If you like doing jewellery designing you can do that at home totally independently. You can also work on freelancing as a marketing executive working from home. Wanna know more, email us on and we will send you information on how you can actually work as a marketing freelancer.

    Internet related work
    This is a very vast field and here sky is the limit. All you need is a computer and Internet facility. Whatever field you are into work at home is perfect match in the software field. You can match your time according to your convenience and complete whatever projects you get. To learn more about how to work from home, contact us today on workfromhome.otr214423@gmail.comand our team will get you started on some excellent work from home projects.

    Diet food
    Since now a days Women & Men are more conscious of the food that they eat hence they prefer to have homemade low cal food and if you can start supplying low cal food to various offices then it will be a very good source of income and not too much of efforts. You can hire a few ladies who will help you out and this can be a good business.

    Thus think over this concept and go ahead.