ftk imager 2.6.1

40
FTK Imager 2.6.1 http://www.accessdata.com/ downloads.html

Upload: esben

Post on 25-Feb-2016

255 views

Category:

Documents


17 download

DESCRIPTION

FTK Imager 2.6.1. http://www.accessdata.com/downloads.html. FTK Imager Interface. Menu Bar. Tool Bar. Evidence Tree View. File List. Native Viewer. Viewer. Properties. Status Bar. Properties General. Properties DOS Attribs & NTFS Info. Properties Access Conrol Entry. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: FTK Imager 2.6.1

FTK Imager2.6.1

http://www.accessdata.com/downloads.html

Page 2: FTK Imager 2.6.1

FTK Imager Interface

Viewer

File List

Evidence Tree View

Properties

Status Bar

Tool Bar

Menu Bar

Native Viewer

Page 3: FTK Imager 2.6.1

PropertiesGeneral

Page 4: FTK Imager 2.6.1

PropertiesDOS

Attribs&

NTFS Info

Page 5: FTK Imager 2.6.1

PropertiesAccess Conrol Entry

Page 6: FTK Imager 2.6.1

InterpretersValues

Page 7: FTK Imager 2.6.1

InterpretersDates

Page 8: FTK Imager 2.6.1

Hex Interpreter

Hex ViewHex Interpreter

Hex Viewer

Page 9: FTK Imager 2.6.1

Right-Click Menu options

Page 10: FTK Imager 2.6.1

Export Files...

Choose where. Go for it!

Page 11: FTK Imager 2.6.1

Export Hash List ...Hash value of each file in directory

Page 12: FTK Imager 2.6.1

Add to Custom Content Image(AD1)

More on this later

Page 13: FTK Imager 2.6.1

Drive Free SpaceUnallocated Space

Page 14: FTK Imager 2.6.1

Unpartitioned Space

Page 15: FTK Imager 2.6.1

FTK ImagerImage a Device

Page 16: FTK Imager 2.6.1

Choose the Device

Page 17: FTK Imager 2.6.1

Where to put it. What to call it

Page 18: FTK Imager 2.6.1

E01 Permits Compression

Page 19: FTK Imager 2.6.1

Single Source - Multiple Images

Page 20: FTK Imager 2.6.1

Multiple Images – Multiple Sources

Once one is started youCan start another.

Page 21: FTK Imager 2.6.1

Progress Success

Page 22: FTK Imager 2.6.1

FTK Creates a Couple of Files

.csv – Listing of files found

.txt – Properties of Device

Page 23: FTK Imager 2.6.1

Details from FTK ImagerInformation for C:\Documents and Settings\Admin\My Documents\Courses\Forensics\Case\Case-USB\

08-0001\Image\08-0001.dd:

Physical Evidentiary Item (Source) Information:[Drive Geometry] Cylinders: 31 Tracks per Cylinder: 255 Sectors per Track: 63 Bytes per Sector: 512 Sector Count: 499,712[Physical Drive Information] Drive Model: Kingston DataTraveler 2.0 USB Device Drive Interface Type: USB Source data size: 244 MB Sector count: 499712[Computed Hashes] MD5 checksum: c78f258d9661b2086bb37658527290f6 SHA1 checksum: ee8f4315cdc0911f0467dfdb5ea8a5148ab415e8

Image Information: Segment list: C:\Documents and Settings\Admin\My Documents\Courses\Forensics\Case\Case-USB\08-0001\08-0001.dd.001

Thu Oct 02 11:40:12 2008 - Image Verification Results: MD5 checksum: c78f258d9661b2086bb37658527290f6 : verified SHA1 checksum: ee8f4315cdc0911f0467dfdb5ea8a5148ab415e8 : verified

Page 24: FTK Imager 2.6.1

List of Undeleted Files

Page 25: FTK Imager 2.6.1

Using FTK ImagerTriage

Page 26: FTK Imager 2.6.1

Choose Source

Page 27: FTK Imager 2.6.1

Find the Image

Page 28: FTK Imager 2.6.1

Image Added to FTK Imager

Page 29: FTK Imager 2.6.1

Explore the Image

Page 30: FTK Imager 2.6.1

Converting from One Format to Another

Open image fileSelect itFile->Export Disk ImageCreate image dialog

AddProvide the requested info

Page 31: FTK Imager 2.6.1

Image Verification

dd Image

EnCase E01 Image

Page 32: FTK Imager 2.6.1

Custom Content Image (AD1)

• Logical images that contain all sorts of content• Portions of a file system• Entire file systems• Individual files or folders• Portions of free space

• Contains content from diverse forensic images• “Case in a file”

Page 33: FTK Imager 2.6.1

Add Content to the Custom Content Image

Page 34: FTK Imager 2.6.1

Create Custom Content Image

Page 35: FTK Imager 2.6.1

Review the Content

Create Image

Page 36: FTK Imager 2.6.1

Create Image

Creates a .csv file of the contents of the AD1 file.

Page 37: FTK Imager 2.6.1

Name and Place

Page 38: FTK Imager 2.6.1

CCI.txtThe Custom Content Image was made from the following list:--------------------------------------------------USB.E01\Partition 1 [243MB]\KINGSTON [FAT16]\[root]\Comp_Sec-II\CS_457.2010.docMD5,SHA1,Filename

"d41d8cd98f00b204e9800998ecf8427e","da39a3ee5e6b4b0d3255bfef95601890afd80709","USB.E01\Partition 1 [243MB]\KINGSTON [FAT16]\[root]\Comp_Sec-II\CS_457.2010.doc\CS_457.2010.doc"

USB.E01\Partition 1 [243MB]\KINGSTON [FAT16]\unallocated space\00412MD5,SHA1,Filename

"9da2a3b792a0d032fd7fd0363886e910","a6dbd978d9512abfba6a170598acf9b78c825120","USB.E01\Partition 1 [243MB]\KINGSTON [FAT16]\unallocated space\00412\00412"

Page 39: FTK Imager 2.6.1

FTK Imager

• Acquisition Tools• Image Formats• FTK Imager Interface• FTK Functionality

Page 40: FTK Imager 2.6.1

Lab

• Sanitize your thumb drive• Make case folder• Seize the thumb drive (Red)• Image the evidence thumb drive (Red)• Write a Imaging Report