F-Response

F-Response

What is F-Response?

F-Response is an easy to use, vendor neutral, patent-pending software utility that enables an investigator to conduct live forensics, Data Recovery, and eDiscovery over an IP network using their tool(s) of choice.  

F-Response is not another analysis tool. F-Response is a utility that allows you to make better use of the tools and training that you already have.

F-Response is a time, travel, and money saving tool.  It extends the capability of your existing arsenal of tools by enabling them to be used over the network; and by leveraging the corporate VPN you can extend the reach of your existing arsenal of tools over the Internet.

F-Response does not require extensive training.  You can learn to use it in 30 minutes, or less.  You can fully leverage the expensive tools and training in which you have already invested.  Other network ready solutions are expensive, require considerable training to use, and force you to use the proprietary integrated vendor analysis tool. 

F-Response is inexpensive, flexible, and vendor neutral.  F-Response is available under three different licensing options (Field Kit Edition, Tactical, Consultant Edition, Enterprise Edition) that are designed to appeal to the varying needs of very small to very large organisations.

Purchase the solution that's right for you - and Extend Your Arsenal

How does F-Response work?

F-Response is based on the well documented iSCSI standard to create a secure, read-only connection between the examiner’s computer and the computer under inspection.  F-Response makes the storage devices on the computer under examination completely accessible to the examiner’s computer where they appear as local, raw, physical storage devices. 

The F-Response connection is completely read-only, functioning much like a software write blocker. F-Response software protects the remote examiner by ensuring that they cannot – even by mistake – alter data stored on the remote computer during the examination.

Licenses are sold on an annual basis with no limitation on the number of installations or uses.  A secure USB key (“FOB”) is utilised to enable the licensing option purchased.  F-Response is available under three different licensing options that are designed to appeal to corporations, consultancies and independent consultants.  These options are as follows:- 

F-Response TACTICAL uses a unique dual dongle/storage device solution that allows an investigator to bring their favourite Windows tools to bear on Windows, Apple, and Linux targets. TACTICAL greatly reduces the need to understand networks and network addressing with an auto-locate technology that gets you connected to your target data quickly and efficiently

F-Response Consultant is a solution that permits many machines to be examined simultaneously over a network. F-Response GUI-based Target code is executed on each machine to be examined. In this case, the F-Response FOB resides at the examiner’s machine

F-Response Enterprise is a solution that permits many machines to be examined simultaneously over a network. F-Response command line or GUI-based Target code is executed on each machine to be examined. The F-Response FOB resides at the examiner's machine, or may support an F-Response server dedicated to live forensics analysis. If a Managed Forensics Service capability is desired, then secure remote access can be provided to the dedicated server (appliance) in order that third party forensics experts can conduct remote examinations on an as-needed basis.

  
  

F-Response Consultant + Covert functions as a single executable ("exe") on the remote target computer that requires no drivers or installation components, as well as no reboot when deployed and started. In addition, the F-Response Consultant Connector and the Covert Console were designed to use minimal resources and are highly portable, requiring only the minimum resources necessary to run Windows XP. F-Response Consultant + Covert is 100% Windows 7 validated and carries the Microsoft Windows 7 Validation logo.