This document provides an overview of using the forensic investigation software EnCase. It describes how EnCase is used to acquire evidence files, verify file integrity, search drives and recover deleted files. Key functions covered include hashing, bookmarking, signature analysis, and generating reports of investigation findings. The document is intended to familiarize users with the main capabilities and workflow of the EnCase forensic software.