¶ … FTK Imager, the Digital Forensic Toolkit
FTK Imager is an imaging and data preview tool used for forensic analysis. Typically, the FTK imager can create disk images for USB and hard drives. The FTK can also create forensic images (perfect copies) of data without altering the original evidence. Moreover, the FTK imager can create MD5 or SHAI hashes of files and be able to recover deleted files from Recycle Bin.
Objective of this project is to investigate the strategy of using the FTK for forensic investigation.
Use of the FTK
The first step is to install the FTK Imager, which can be accessed from the following website: http://accessdata.com/product-download/?/support/adownloads
After opening the webpage, the current releases of the digital forensic tools appear ad being revealed below:
Then, click FTK Image and Click the FTK Imager, version 3.4.2, and Click download. After completing the installation, the next section discusses the method of adding a file folder or file as evidence.
1.Method of Adding a file folder or an individual file as Evidence
Method to add a file folder or an individual file as evidence is as follows:
Select file from the top left of the folder
Select Add Evidence Item
Select Source, and (Physical Drive, Image file, Logical Drive, and Contents of a file) appears
PHYSICALDRIVE appears under Evidence Tree as revealed below:
2.Differences between HEX view and TEXT view
Text view allows an individual to view a file content as Unicode or ASCII characters. The text view can assist in viewing binary and text data, which is not visible when the file is in its native form. On the other hand, Hex view refers to byte of data in a file, which is in hexadecimal code.
The following procedure is used for Text View .
Text View
Select View files in plain text
Select Add Evidence Item
Select Source (Physical Drive, Image file, Logical Drive, and Contents of a file) appear
Click Next
Click Finish
Double...
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now