SAFE · Examiner · Nodes · Agent Fleet
EnCase deployment and recovery
The upgrade completed on Saturday. On Monday the examiner opens, the console looks normal, and not one endpoint has checked in since. Somewhere between a certificate, a service account, and a port, the environment stopped being able to reach anything.
EnCase environments fail quietly.
Nothing crashes. Services report as running. The examiner connects to the SAFE, the case opens, the node list is fully populated. What has actually happened is that the agents stopped completing check-ins three weeks ago, and the first person to discover it is an investigator who needed a snapshot from a machine today. Almost every environment we are called into failed at a boundary rather than in a component: a certificate that expired, a service account whose password rotated, a proxy rule that changed, a SQL instance that moved.
The product is rarely the problem. The seams are.
Scope
What gets fixed
SAFE, examiner, and node communication
Endpoints that will not check in, nodes that show as connected but never return results, and examiners that authenticate but cannot enumerate. Traced from the agent outward until the break is located rather than guessed at.
Certificates and PKI
Expired or mismatched certificates, incomplete chains, missing intermediates on endpoints, key files that no longer match the SAFE they were issued for, and the renewal that was performed correctly on the server and never distributed to the fleet.
SQL backend
Connection strings, authentication mode and permissions, instances that were migrated without the application knowing, database growth and index health, and the recovery of a backend that no longer matches the version of the application in front of it.
Reverse proxy and port configuration
Web service bindings, reverse proxy rules, load balancer health checks, firewall paths between agents and infrastructure, and the network changes that silently removed a route the product had been depending on.
Active Directory and service accounts
Service account permissions, delegation, rotated or expired passwords, group policy that overrides local configuration, and authentication paths that break when a domain controller or trust relationship changes.
Agent and endpoint fleet health
Version drift across the estate, deployment through existing software distribution, agents blocked by endpoint protection, and reconciliation of what the console believes is installed against what is actually running.
Upgrades
Upgrade, recovery, and rollback
Version upgrades are where most of these environments break, and they break after the maintenance window has closed. The work is the same whether we are running the upgrade or arriving after one has gone wrong.
- Pre-upgrade assessment. Current version, backend, certificate expiry, service account state, and agent version spread documented before anything is touched, so there is a known good state to return to.
- Rollback path established first. Backups verified as restorable rather than assumed, with the rollback sequence written down before the upgrade begins.
- Post-upgrade recovery. For environments already non-functional after a version change, diagnosis of what the upgrade altered, followed by repair forward or a return to the prior version, whichever the evidence supports.
- Validation against a live endpoint. Sign-off means a real snapshot pulled from a real machine, not a green status page. An environment is working when it produces evidence.
- Licensing and entitlement. License server reachability, seat allocation, and entitlement mismatches that present as unrelated failures.
Engagement model
Remediation of an environment you already own
4n6PI is engaged per matter, by written work authorization, to fix or stand up an EnCase Endpoint Investigator environment the organization has already licensed. The engagement has a defined start, a defined end, and a validated environment in between.
- Your licensing, your infrastructure. No product is resold and nothing is hosted on our side. The environment stays entirely under the organization's ownership and administration.
- Not a managed program. This is not ongoing administration, health checking, or standing coverage of the platform. When the environment is validated and the internal team has the documentation, the engagement is over.
- Knowledge transfer is part of the deliverable. Configuration as-built, what was changed and why, and the checks to run before the next upgrade, written for the administrator who inherits it.
- Remote by default. Nearly all of this work is performed over the organization's existing remote access. On-site is arranged when the environment requires it.
Where the depth comes from
This is the service 4n6PI is least often matched on. The examiners who perform it have run EnCase Endpoint Investigator as administrators and investigators at enterprise scale, across large distributed fleets, through version migrations and broken environments, in production, with active matters waiting on the result. That is a narrow specialty, and it is not one a general consultancy staffs.
Engage
When to call
- An upgrade completed and the environment has not worked since
- Endpoints stopped checking in after a network, certificate, or domain change
- The console shows nodes as healthy but no job ever returns results
- A new deployment authenticates correctly and still cannot reach the fleet
- The administrator who built the environment has left and nobody knows how it was configured
- A matter is waiting and the platform that was supposed to collect the evidence is down
If a matter cannot wait for the environment to be repaired, 4n6PI can preserve the affected systems directly. Forensic collection does not depend on the platform being healthy.
An environment that cannot reach its endpoints holds no evidence
It only looks like a platform problem until the day someone needs something off a machine. Then it is an evidence problem.