by Chirath De Alwis
Forensic Toolkit or FTK is a computer forensics software product made by AccessData. This is a Windows based commercial product. For forensic investigations, the same development team has created a free version of the commercial product with fewer functionalities. This FTK Imager tool is capable of both acquiring and analyzing computer forensic evidence.
The evidence FTK Imager can acquire can be split into two main parts. They are:
1. Acquiring volatile memory
2. Acquiring non-volatile memory (Hard disk)
There are two possible ways this tool can be used in forensic image acquisitions.