Evidence Acquisition Using Accessdata FTK Imager

by Chirath De Alwis

Forensic Toolkit or FTK is a computer forensics software product made by AccessData. This is a Windows based commercial product. For forensic investigations, the same development team has created a free version of the commercial product with fewer functionalities. This FTK Imager tool is capable of both acquiring and analyzing computer forensic evidence.

The evidence FTK Imager can acquire can be split into two main parts. They are:

1. Acquiring volatile memory
2. Acquiring non-volatile memory (Hard disk)

There are two possible ways this tool can be used in forensic image acquisitions.

Read More

Leave a Comment