FTK Imager a Forensics Tools For MAC OS X
-
Updated
Jul 26, 2018
8000
FTK Imager a Forensics Tools For MAC OS X
CLI Tools to open, extract and mount FTK Imager's AccessData AD1 forensic images on linux.
This report was written for the Digital Forensics Analysis coursework, specifically the first assignment. In which, steps and screenshots for each investigation process are recorded.
A tool written in AHK to automate FTK imager for collection purposes.
Performed a forensic investigation on a digital evidence image file using Autopsy. Analyzed metadata, recovered deleted files, and documented findings.
Memory Forensics & Malware Investigation using FTK Imager, Volatility & Autopsy
Complete digital forensic investigation of the M57-Jean dataset with documented methodology, findings, and forensic report.
Digital Forensics & Incident Response Lab | CHFI | Evidence Analysis | Forensic Investigations
A collection of digital forensics lab reports covering Linux artifact recovery, shell history analysis, bash script forensics, and incident reconstruction using tools like SleuthKit, Auditd, and command-line utilities.
Practical forensic recovery cases involving MBR repair, GPT reconstruction, partition recovery, and file evidence validation using hex analysis and FTK Imager.
MFT-Recover is a file recovery tool for the Windows NTFS 3.1 file system, used since Windows XP through the latest Windows 11. The tool works by parsing Master File Table (MFT) entries and directly accessing the raw volume to retrieve the data of deleted files.
Run FTK Imager directly from a portable USB or WinFE environment to perform forensic imaging without installing software on the target system.
Using FTK Imager to create and verify a forensic image of a USB drive.
A write-up about the CyberDefenders Lab Phishy
CS6503 Digital Forensics
using FTK imager to extract data from disk
Digital forensics investigation report for a Linux insider threat lab using FTK Imager, Bash history, log analysis, and artifact correlation.
Forensic imager with FTK Imager-compatible output — bit-for-bit E01/raw acquisition, targeted logical collection, read-back verification, resume. Pure Python 3.10+, stdlib only.
Hands-on digital forensics investigations using FTK Imager, Autopsy, Magnet AXIOM, and Windows forensic artifacts.
Covert DD images to E01's using FTK Imager
Add a description, image, and links to the ftk-imager topic page so that developers can more easily learn about it.
To associate your repository with the ftk-imager topic, visit your repo's landing page and select "manage topics."