Professional Documents
Culture Documents
The FTK allows you to manage your investigations by assigning a case for each of them. The case information
is stored in a database.
°° Processing Profile: Configure the default processing options for the case by either using a processing
profile or custom settings. This item will be detailed in the next topic.
°° Open the case: Check this option if you wish to open the case as soon as it is created. After the fields are
filled, click on OK to create the new case.
3. The next step is to add the evidence file, as shown in the
following screenshot:
°° Acquired Image(s): Select this type to add an image file (dd, e01, AD1,and so on)
°° All Images in Directory: Select this to add all images in a specific folder
°° Contents of a Directory: Select this type to add all files in a specific folder
°° Individual File(s): Select this to add a single file (docx, pdf, jpg, and so on)
°° Physical Drive: Select this to add a physical device (a full hard disk)
°° Logical Drive: Select this to add a logical volume or partition, for example, the C or D drive
6. Once all the parameters are configured, click on OK and wait for the evidence processing.
[Incorrect use of the Time Zone option can produce inconsistent results because it changes all MAC time values of
evidence. If you do not know the Time Zone option of the evidence, use the FTK registry viewer tool to identify it]
6. Once all the parameters are configured, click on OK and wait for the evidence processing.
[Incorrect use of the Time Zone option can produce inconsistent results because it changes all MAC time values of
evidence. If you do not know the Time Zone option of the evidence, use the FTK registry viewer tool
to identify it.
The FTK interface
The main feature of the FTK interface is the location, organization, and exportation of data. The interface
contains tabs, each with a specific focus, and also contains a common toolbar and file list with customizable
columns. New tabs can be added to help the localization of information as shown in the following screenshot:
3. Select the drive or browse to the source you want to preview and then click on Finish:
4. The evidence item appears in the Evidence Tree pane:
Creating forensic images
Once the item is added to the evidence, you can perform the process of creating a forensic image. FTK Imager
allows you to make several different types of forensic images. In addition, drive content and hash lists can be
exported.