FTK Imager a Forensics Tools For MAC OS X
-
Updated
Jul 26, 2018
FTK Imager a Forensics Tools For MAC OS X
CLI Tools to open, extract and mount FTK Imager's AccessData AD1 forensic images on linux.
This report was written for the Digital Forensics Analysis coursework, specifically the first assignment. In which, steps and screenshots for each investigation process are recorded.
A tool written in AHK to automate FTK imager for collection purposes.
MFT-Recover is a file recovery tool for the Windows NTFS 3.1 file system, used since Windows XP through the latest Windows 11. The tool works by parsing Master File Table (MFT) entries and directly accessing the raw volume to retrieve the data of deleted files.
Performed a forensic investigation on a digital evidence image file using Autopsy. Analyzed metadata, recovered deleted files, and documented findings.
Guia de forense digital: metodologia, hashes, Sleuth Kit e IPED. PT/EN.
Memory Forensics & Malware Investigation using FTK Imager, Volatility & Autopsy
Practical forensic recovery cases involving MBR repair, GPT reconstruction, partition recovery, and file evidence validation using hex analysis and FTK Imager.
Digital Forensics & Incident Response Lab | CHFI | Evidence Analysis | Forensic Investigations
Complete digital forensic investigation of the M57-Jean dataset with documented methodology, findings, and forensic report.
Using FTK Imager to create and verify a forensic image of a USB drive.
A collection of digital forensics lab reports covering Linux artifact recovery, shell history analysis, bash script forensics, and incident reconstruction using tools like SleuthKit, Auditd, and command-line utilities.
Run FTK Imager directly from a portable USB or WinFE environment to perform forensic imaging without installing software on the target system.
Digital forensics case study demonstrating evidence acquisition, integrity verification, deleted-data recovery, and artifact analysis.
CS6503 Digital Forensics
using FTK imager to extract data from disk
End-to-end digital forensics lab — forensic image acquisition with FTK Imager (E01 format, MD5/SHA-1 verification) and deleted file recovery & artifact analysis with Autopsy (The Sleuth Kit). Recovered 70+ deleted files from unallocated NTFS sectors. Educational DFIR project aligned with NIST SP 800-86.
A write-up about the CyberDefenders Lab Phishy
Digital forensics investigation report for a Linux insider threat lab using FTK Imager, Bash history, log analysis, and artifact correlation.
To associate your repository with the ftk-imager topic, visit your repo's landing page and select "manage topics."