FTK User Manual
Total Page:16
File Type:pdf, Size:1020Kb
AccessData Corp. Legal Notices AccessData Corp. makes no representations or warranties with respect to the contents or use of this documentation, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, AccessData Corp. reserves the right to revise this publication and to make changes to its content, at any time, without obligation to notify any person or entity of such revisions or changes. Further, AccessData Corp. makes no representations or warranties with respect to any software, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. Further, AccessData Corp. reserves the right to make changes to any and all parts of AccessData software, at any time, without any obligation to notify any person or entity of such changes. You may not export or re-export this product in violation of any applicable laws or regulations including, without limitation, U.S. export regulations or the laws of the country in which you reside. © 2008 AccessData Corp. All rights reserved. No part of this publication may be reproduced, photocopied, stored on a retrieval system, or transmitted without the express written consent of the publisher. Version 1.80.0 May 22, 2008 AccessData Corp. 384 South 400 West Lindon, Utah 84042 U.S.A. www.accessdata.com ii Forensic Toolkit User Guide AccessData Corp. AccessData Trademarks AccessData is a registered trademark of AccessData Corp. Distributed Network Attack is a registered trademark of AccessData Corp. DNA is a registered trademark of AccessData Corp. Forensic Toolkit is a registered trademark of AccessData Corp. FTK is a trademark of AccessData Corp. FTK Imager is a trademark of AccessData Corp. Known File Filter is a trademark of AccessData Corp. KFF is a trademark of AccessData Corp. LicenseManager is a trademark of AccessData Corp. Password Recovery Toolkit is a trademark of AccessData Corp. PRTK is a trademark of AccessData Corp. Registry Viewer is a trademark of AccessData Corp. Ultimate Toolkit is a trademark of AccessData Corp. Third-Party Trademarks All third-party trademarks are the property of their respective owners. iii AccessData Corp. iv Forensic Toolkit User Guide CONTENTS Audience . 2 Handling Evidence. 2 Role of Forensic Toolkit . 3 Other AccessData Products . 3 Password Recovery Software . 4 FTK 2.0 . 4 Chapter 1 FTK Overview The Big Picture. 6 Acquiring and Preserving the Evidence. 7 Analyzing the Evidence . 8 Hashing . 8 Known File Filter . 9 Searching . 9 Presenting the Evidence . 10 Chapter 2 Installing the Forensic Toolkit . 11 System Requirements . 12 Supported File Systems and Image Formats . 13 System Preparation. 14 Basic Installation . 15 Basic Install from CD . 16 Basic Install from Downloadable Files . 19 Upgrade Instructions . 27 Upgrading from CD . 27 Upgrading from Downloadable Files . 28 Uninstalling . 30 Chapter 3 Getting Started Starting FTK . 32 v AccessData Corp. Using the Start Menu . 32 Using the Command Line . 32 Using the Case File . 33 Using the Dongle . 33 Using the FTK Startup Menu . 33 Overview Window . 34 Evidence and File Items. 35 File Status . 36 File Category. 37 Explore Window . 39 Graphics Window . 40 E-mail Window . 41 Search Window . 42 Indexed Search . 43 Live Search . 44 Bookmark Window . 45 Toolbar Components. 48 Viewer Toolbar . 48 Tree List Toolbar . 49 File List Toolbar . 50 File List Columns . 51 FTK Imager . 54 Using LicenseManager . 55 Starting LicenseManager . 56 Chapter 4 Starting a New Case Starting a Case . 60 Completing the New Case Form . 61 Entering Forensic Examiner Information . 63 Selecting Case Log Options . 64 Selecting Evidence Processes. 65 Refining the Case . 69 Refining the Index . 74 Managing Evidence. 78 Adding Evidence . 78 Editing Evidence . 81 Removing Evidence . 81 Refining Evidence . 81 Reviewing Case Summary . 88 Processing the Evidence . 89 vi Forensic Toolkit User Guide AccessData Corp. Backing Up the Case . 90 Storing Your Case Files . 90 Recovering Evidence from a System Failure . 90 Backing Up Cases Automatically . 91 Chapter 5 Working with Existing Cases Opening an Existing Case . 94 Opening an Existing Case from a Different Location . 94 Opening a Case in Case Agent Mode (Read-only) . 95 Using the Case Agent Mode Manager . 95 Adding Evidence . 99 Completing the Add Evidence Form . 100 Selecting Evidence Processes. 101 Managing Evidence. 103 Refining the Index . 113 Reviewing Evidence Setup . 117 Processing the Evidence . 118 Viewing File Properties . 119 General Info . 120 File Source Info . 121 File Content Info . 122 Case-Specific Info . 123 E-mail Info . 125 Setting Up Multiple Temporary Files . 126 Chapter 6 Processing Evidence Using Bookmarks . 128 Creating a Bookmark . 128 Adding Files to a Bookmark . 130 Removing a Bookmark . 131 Creating Thumbnails . 131 Importing KFF Hashes . 132 Verifying Image Integrity . 133 Using Analysis Tools . 135 Using the Case Log. ..