Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

What Is Forensic Toolkit (FTK) ?

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 7

AccessData Forensic ToolKit Features

Reporting and Monitoring

 Easy-to-use GUI with automated preprocessing of forensic data.


 The broadest OS support and analysis on the market.
 Advanced filtering and automated data categorization.
 Do it all. Preview, acquisition, mounting and analysis of live data.
 Flexibility. Available as a perpetual or subscription license.
 Native support for Volume Shadow Copy.
 Comprehensive volatile memory analysis.
 Add-on Cerberus for automated malware analysis and triage.
 Password cracking through PRTK/DNA.
 Visualization capabilities allow graphic analysis of file and email data.

Benefits

 Integrated Computer Forensic Solution.


 Unmatched Processing.
 Handle massive data sets without crashing or loosing work.
 Feature rich out of the box.
 Fast, Comprehensive index and Binary searching.
 File and Disk Encryption Support.
 Advanced gallery view for images and video with eid.
 Superior Email Analysics.
 Single-Node enterprise (Remote Investigration).
 Volatile and Memory Analysics.
 Internet Artifact Analysics.

What Is Forensic Toolkit (FTK)?

FTK is intended to be a complete computer forensics


solution. It gives investigators an aggregation of the
most common forensic tools in one place. Whether
you are trying to crack a password, analyze emails,
or look for specific characters in files, FTK has got
you covered. And, to sweeten the pot further, it
comes with an intuitive GUI to boot.
There are a few distinguishing qualities that set FTK
apart from the rest of the pack. First and foremost is
performance. Subscribing to a distributed processing
approach, it is the only forensic software that utilizes
multi-core CPUs to parallelize actions. This results
in a momentous performance boost; – according to
FTK’s documentation, one could cut case
investigation time by 400% compared to other tools,
in some instances.

Another unique feature of FTK is its use of a shared


case database. Rather than having multiple working
copies of data sets, FTK uses only a single, central
database for a single case. This enables team
members to collaborate more efficiently, saving
valuable resources. The use of a database also
provides stability; unlike other forensics software
that solely rely on memory, which is prone to
crashing if capacity exceeds limits, FTK’s database
allows for persistence of data that is accessible even
if the program itself crashes.
Robust searching speeds are another hallmark of
FTK. Due to the tool’s emphasis on indexing of files
up front, investigators can greatly reduce search
times. FTK generates a shared index file, which
means that you don’t need to duplicate or recreate
files.
Which Tools Does It Contain? What Are Those Tools
Used For?

As stated above, FTK is designed as an all-in-one


digital forensics solution. Some of its major
capabilities include:

 Email Analysis
FTK provides an intuitive interface for email analysis
for forensic professionals. This includes having the
ability to parse emails for certain words, header
analysis for source IP address, etc.

 File Decryption
A central feature of FTK, file decryption is arguably
the most common use of the software. Whether you
want to crack passwords or decrypt entire files, FTK
has an answer for it. You can retrieve passwords for
over 100 applications with FTK.

 Data Carving
FTK includes a robust data carving engine.
Investigators have the option to search files based on
size, data type, and even pixel size.

 Data Visualization
Evidence visualization is an up-and-coming
paradigm in computer forensics. Rather than
analyzing textual data, forensic experts can now use
various data visualization techniques to generate a
more intuitive picture of a case. FTK empowers such
users, with timeline construction, cluster graphs,
and geolocation.

 Web Viewer
One of the more recent additions to the suite, the
FTK Web Viewer is a tool that accelerates case
assessments by granting access of case files to
attorneys in real time, while evidence is still being
processed by FTK. It also allows for multi-case
searching, which means that you don’t have to
manually cross-reference evidence from different
cases.

 Cerberus
Embracing the shift towards analytics, FTK has
included a powerful automated malware detection
feature called Cerberus. It uses machine intelligence
to sniff malware on a computer, subsequently
suggesting actions to deal with it if found.
 OCR
Another feature that borrows heavily from AI and
computer vision, FTK’s Optical Character
Recognition engine allows for fast conversion of
images to readable text. Multi-language support is
also included.
What Is the FTK Imager? How Is the FTK Imager
used?

Though we’ve established just how versatile a toolkit


FTK is for forensic investigations, it is never a good
idea to start feeding it the original files. A sound
forensic practice is to acquire copies (images) of the
affected system’s data and operate on those copies.
To aid in this process, Access Data offers
investigators a standalone disk imaging software
known as FTK Imager.
In addition to creating images of hard drives, CDs
and USB devices, FTK Imager also features data
preview capabilities. This can be used to preview
both files/folders and the contents residing in those
files. FTK Imager also supports image mounting,
which enhances its portability. The tool is one of
very few that can create multiple file formats: EO1,
SMART, or DD raw. You can also easily track
activities through its basic text log file.
While creating copies of original disk drives, a
critical aspect is to check file integrity. FTK Imager
also assists in this area, with support for creating
MD5 and SHA1 hashes. Furthermore, you can
generate hash reports that can be archived for later
use. For instance, if you want to check whether an
image has been changed since its acquisition.
Once you’ve created images of disk drives using FTK
Imager, you can then move on to a more thorough
investigation of the case with FTK.

You might also like