1.2k likes | 1.25k Views
FTK. Components Preview Acquisition New Case Setup Adding Evidence. FTK - Components. FTK – Forensic Toolkit, FTK Imager, License manager, Password Recovery Toolkit, Register Viewer, etc. FTK – Components License Manager. License Manager Add or remove licenses from your dongle.
E N D
FTK Components Preview Acquisition New Case Setup Adding Evidence
FTK - Components • FTK – Forensic Toolkit, FTK Imager, License manager, Password Recovery Toolkit, Register Viewer, etc.
FTK – Components License Manager • License Manager • Add or remove licenses from your dongle. • Purchase additional licenses. • Renew your subscription. • Download product updates. • Start > All Programs > AccessData > LicenseManager > LicenseManager
FTK – Components Password Recovery Tool Kit • PRTK – Password Recovery Tool Kit
FTK – Components Registry Viewer • AccessData Registry Viewer • Registry Viewer provides access to a registry’s protected areas, which contain useful forensic data not accessible in Windows regedit.
FTK – Components Registry Viewer • Some of the forensic data found in the registry files consists of: • Usernames and passwords • A history of Internet sites accessed, including date and time • A record of Internet searches performed on Google, Yahoo, etc. • Lists of recently accessed files • A list of all programs installed on the system
FTK Imager Preview Acquisition
FTK – Imager • FTK Imager • Used to make a copy of a device (i.e., hard drive, CD, thumb drive, etc.) • Imager Screens • Evidence Tree, File List, Properties, Viewer
FTK Imager - Preview • Physical drives – Used to image an entire HD. • Logical drives – Used to image a single partition (A, C, D, etc).
FTK Imager - Preview • In the File List window, click once on the second item. • In the Properties window, note the Date Accessed.
FTK Imager - Preview • Exit out of FTK Imager and open My computer > A drive. • Note that only one item is listed on the floppy. • After you open the file, close the picture and exit out of the floppy window and My Computer.
FTK Imager - Preview • Once again, start FTK Imager. • Add the “A” drive as evidence. • Select the second file and note the date stamp.
FTK Imager - Preview • Preview of the Recycle bin • SID • Info2 files
FTK Imager - Preview • Preview of unallocated space.
FTK Imager - Preview • Preview of unallocated space cont. • Note the text.
FTK Imager - Preview • Preview mode allows you to export items of interest without changing the data.
FTK Imager - Preview • Exporting items in class. • Class labs will be located on the Forensics partition. • Items exported from your cases should be stored on the “F” drive.
FTK Imager - Acquisition • Image types • EnCase .E01 • SMART .S01 • Linux dd • FTK can read: • Encase • SMART • Linux dd • WinImage • Ghost • ICS • Safeback • CUE and ISO
FTK Imager - Acquisition • Physical drive – Represents the entire contents of a hard drive, includes all partitions. • Logical drive - Represents the contents of a single partition or Windows drive letter.
FTK Imager - Acquisition • Logical Drive selection • Note, your Drive Selection options change.
FTK Imager - Acquisition • Click on the Add button. This will bring up the Select Image Type screen. • Select Image Type • CD or DVD – This screen is omitted since the image is created as ISO or CUE.
FTK Imager - Acquisition • Enter an Case Number: • Such as (070522-010) • Year 07, month 05 day 22. The 010 allows multiple cases in a given day. • Enter an Evidence Number: • Such as (0010) • The 0010 allows additional data to be added to the case at a later date. • Case Name. • It’s a good idea to add device type in name i.e., desktop, floppy, laptop, etc. • Example: smithdesktopHD1, smithdesktopHD2, smithfloppy1, etc.
Forensic Toolkit (FTK) New Case Setup Adding Evidence General Settings
FTK – New Case Setup • Start a new case • Open an existing case • Preview evidence • This option will startup FTK Imager. • Go directly to work
FTK – New Case Setup • Case Number • Note! Case Number doesn’t include the Evidence Number • What’s wrong with the case number? • Case Name • Note! The name is appended to the path to create the a case folder.
FTK – New Case Setup • Depending on your site policy you may or may not have to complete this screen. • Select Next.
FTK - New Case Setup • Case Log Options • Allows you to determine what to include in the case log file. • It documents case activities. • The log file is called: • FTK.log • Located in the case folder. • Usage • Reports • Identifying case status/progress. • Manually modifiable • Tools > Add Case Log Entry
FTK - New Case Setup • KFF - Skip system files • Entropy - Skip encrypted file indexing • Full Text Index - Longest step in case creation.
FTK - New Case Setup • Decrypt EFS Files - Requires PRTK to decrypts EFS files. • File Listing DB - MS Access db of files • Dave Carve - Finds files embedded in other files and free space.
FTK - New Case Setup • Data Carving: • Picture - Porn • PDF – Theft of intellectual property. • HTML – Porn, time charging, etc. • AOL/AIM – Time charging, theft of intellectual property. • Office Documents - Time charging, theft of intellectual property.
FTK - New Case Setup • Only use the “Include All Items” option!!!
FTK - New Case Setup • Don’t limit yourself.
FTK - New Case Setup • You have now finished defining the global settings for this case and are ready to add an image file. • Select Add Evidence.