Professional Documents
Culture Documents
Sc Computer Science
CYBER FORENSICS
COMPILED BY :
https://www.profajaypashankar.com
1. Click File, and then Create Disk Image, or click the button on the
tool bar.
X
PAccecData FTKImager 34.2.6
le ylew Mode Heb
Add EVdence Iam...
S Add AJ Attached Derices File Lit
Date Moditied
Ige Mounting.. Name Sze Type
A Ramove Evidance Item
Reove Al Edence Ts
a ceate Disk Irege..
Bxoort Dek Irage..
EDrt Logical Iaga (AD1).
Add to Custom Content Iage (ADL)
Ceate Custom Content Iraçe (AD1)...
Decypt ADI mage.
YerfY Diive/ ITage..
Capure Nemory...
btain Protected Fies...
Datect EFS En crypton
| E t Fles
Expot Fle Hasth ist.
Exoot Directory Listing..
Ext
Save
2. Select the source evidence type you want to make an image of and
click Next.
Select Source X
Image Source
D:\bysnslpractcal
Start1ng Evidence tlumber:
Image Destinabon(s)
Case Nunber: 1
Evidence Number:
Notes:
4. In the Image Destination Folder field, type the location path where
you want to save the image file, or click Browse to find to the desired
location.
5. After adding the image destination path click on finish and start the
image processing.
Creating Image X
Elapsed time:
Estimated time left:
OK
Custorn Conte...
Adds evidence from disk, image fie, or foder
C Physical Dive
CLogjcal Dive
C Image Fle
CContents of a Folder
logical fle level analysis only: excudes deleted, unallocated, ctc)