
Exterro’s FTK Imager is a free tool for creating forensic images of digital devices. It allows users to preview data, create exact copies without altering the original evidence, and generate hash reports to verify data integrity.
Vendor
Exterro
Company Website
Create Forensic Images with Exterro FTK Imager
Join the thousands of forensic professionals worldwide who rely on FTK Imager, the forensic industry’s preferred data imaging and preview solution, for the first step in investigating an electronic device.
Quickly assess electronic evidence, create forensic images, and generate hash reports.
FTK Imager is a free data preview and imaging tool used to acquire electronic evidence in a forensically sound manner by creating copies of computer data without making changes to the original evidence.
Create Forensic Images
With FTK Imager, you can create forensic images of local hard drives, CDs and DVDs, thumb drives or other USB devices.
Preview Data
Preview the contents of forensic images stored on a local machine or on a network drive.
Evaluate Evidence
Evaluate computer evidence to determine if further analysis with a forensic tool such as the FTK® Forensic Toolkit is warranted.
Create perfect copies of computer data with Full-Disk Imaging.
FTK Imager can create perfect copies (i.e., forensic images) of computer data without making changes to the original evidence. The forensic image is identical in every way to the original, including file slack and unallocated space or drive free space. Keep evidence safe from harm or tampering while the investigation proceeds using the image.
Recreate the device user’s perspective with Image Mounting.
Mount an image for a read-only view that leverages Windows® File Explorer to see the content of the image exactly as the user saw it on the original drive. Recover files that have been deleted from the Recycle Bin, but have not yet been overwritten. Run virus scans or Python scripts on a mounted image to easily show a jury how a user would have seen their own files and folder structure.
Prove the integrity of your case evidence with Hash Reports.
Generate hash reports for regular files and disk images, including files inside disk images, that you can later use as a benchmark to prove the integrity of your case evidence. Hashes generated by FTK Imager can be used to verify that the image and the original drive are identical and that the image has remained unchanged since acquisition.
Additional Capabilities
Custom Content Images
Create a custom content image of your dataset by selecting only the data you want to image in order to reduce the size of your dataset and make your investigation more efficient, yet still forensically sound.
Data Preview
Preview the contents of forensic images stored on a local machine or on a network drive before imaging it. Preview files and folders on local hard drives, network drives, CDs and DVDs, thumb drives or other USB devices.
RAM Capture
Perform memory capture or registry capture on a live device to recover passwords or other data stored in memory on the active device.
Export Files
FTK Imager can write and read all of the most common forensic image formats, making it easy to continue your forensic analysis and review in another tool, including the full-featured FTK Forensic Toolkit.