FTK Imager a Forensics Tools For MAC OS X
-
Updated
Jul 26, 2018
FTK Imager a Forensics Tools For MAC OS X
CLI Tools to open, extract and mount FTK Imager's AccessData AD1 forensic images on linux.
This report was written for the Digital Forensics Analysis coursework, specifically the first assignment. In which, steps and screenshots for each investigation process are recorded.
A tool written in AHK to automate FTK imager for collection purposes.
Memory Forensics & Malware Investigation using FTK Imager, Volatility & Autopsy
Performed a forensic investigation on a digital evidence image file using Autopsy. Analyzed metadata, recovered deleted files, and documented findings.
A collection of digital forensics lab reports covering Linux artifact recovery, shell history analysis, bash script forensics, and incident reconstruction using tools like SleuthKit, Auditd, and command-line utilities.
Practical forensic recovery cases involving MBR repair, GPT reconstruction, partition recovery, and file evidence validation using hex analysis and FTK Imager.
Using FTK Imager to create and verify a forensic image of a USB drive.
MFT-Recover is a file recovery tool for the Windows NTFS 3.1 file system, used since Windows XP through the latest Windows 11. The tool works by parsing Master File Table (MFT) entries and directly accessing the raw volume to retrieve the data of deleted files.
CS6503 Digital Forensics
using FTK imager to extract data from disk
Covert DD images to E01's using FTK Imager
Digital forensics investigation report for a Linux insider threat lab using FTK Imager, Bash history, log analysis, and artifact correlation.
Run FTK Imager directly from a portable USB or WinFE environment to perform forensic imaging without installing software on the target system.
Forensische Analyse eines selbst erstellten USB-Stick-Images – Rekonstruktion gelöschter und manipuliert gespeicherter Dateien mit Autopsy.
Forensic investigation of a 40 GB Seagate Barracuda HDD acquired via WiebeTech UltraDock v5.5. Includes full expert witness report, FTK acquisition log, and photographic exhibits.
Timelining a reverse shell compromise with FTK Imager.
Browser-based AccessData AD1 logical image viewer — pure-stdlib Python parser + zero-dependency web UI. Open .ad1 evidence on Mac/Linux/Windows without FTK Imager.
Computer forensic using autospy, wireshark, etc.
Add a description, image, and links to the ftk-imager topic page so that developers can more easily learn about it.
To associate your repository with the ftk-imager topic, visit your repo's landing page and select "manage topics."