Forensic Acquisition in Windows - FTK Imager

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ต.ค. 2024
  • In this video we will use FTK Imager to create a physical disk image of a suspect drive connected to our forensic workstation via a write blocker. FTK Imager is a GUI tool for copying various types of data for forensic acquisition purposes.
    🚀 Full Digital Forensic Courses → learn.dfir.sci...
    010001000100011001010011011000110110100101100101011011100110001101100101
    Get more Digital Forensic Science
    👍 Subscribe → bit.ly/2Ij9Ojc
    ❤️ YT Member → bit.ly/DFIRSci...
    ❤️ Patreon → / dfirscience
    🕸️ Blog → DFIR.Science
    🤖 Code → github.com/DFI...
    🐦 Follow → / dfirscience
    📰 DFIR Newsletter → bit.ly/DFIRNews
    010100110111010101100010011100110110001101110010011010010110001001100101
    Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please link back to the original video. If you want to use this video for commercial purposes, please contact us first. We would love to see what you are doing.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 77

  • @sahenders1
    @sahenders1 4 ปีที่แล้ว +1

    Well done! Thank you for such a detailed demonstration.

    • @DFIRScience
      @DFIRScience  4 ปีที่แล้ว

      You're very welcome!

  • @madhuraneniyashwanth5739
    @madhuraneniyashwanth5739 2 ปีที่แล้ว

    This is so helpful and clear detailed explanation ,thank you so much

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว

      Glad it was helpful!

  • @TheMrmuaz
    @TheMrmuaz 3 ปีที่แล้ว +3

    Well that's a really clear explanation, thank you.

  • @nicholasedwardsillett1259
    @nicholasedwardsillett1259 2 ปีที่แล้ว +4

    I have an assessment due tonight and this helped me a lot. Thank you so much

  • @harinandan6557
    @harinandan6557 3 วันที่ผ่านมา

    Hey i am struggling to do the image thing where it’s downloading but it’s taking too much of the space and later saying failure this is for an assignment I don’t know why it’s taking 1 million mb or kb and failing the process so could you explain please?

  • @charlesbergvi6705
    @charlesbergvi6705 2 ปีที่แล้ว +3

    I cant stress enough how much this has helped for my upcoming assignment, prime content my friend, thankyou...

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว +2

      Glad to hear it. Let me know if you need videos on any other topics!

  • @Zahidhuseynovs-c3s
    @Zahidhuseynovs-c3s 14 วันที่ผ่านมา

    Miller Deborah Young Susan Robinson Matthew

  • @JasonTollefson
    @JasonTollefson 26 วันที่ผ่านมา

    Gonzalez Dorothy Jones Charles Thompson Melissa

  • @SusanBeall-p6o
    @SusanBeall-p6o 28 วันที่ผ่านมา

    Gonzalez Larry Robinson Cynthia Hall John

  • @KakulyHatun-d8v
    @KakulyHatun-d8v หลายเดือนก่อน

    Wilson Cynthia Harris William Walker Edward

  • @DoraSpring-m9o
    @DoraSpring-m9o 26 วันที่ผ่านมา

    Harris Dorothy Clark Mary Anderson Eric

  • @LaboniJahan-x8s
    @LaboniJahan-x8s 21 วันที่ผ่านมา

    Davis Mary Moore Linda Jackson Paul

  • @SethLam-u1e
    @SethLam-u1e 26 วันที่ผ่านมา

    Martinez Larry Wilson Ruth Hall Anna

  • @AmyBurnett-w8n
    @AmyBurnett-w8n 28 วันที่ผ่านมา

    Gonzalez Karen Perez Joseph Perez William

  • @DarrellHolmes-q3u
    @DarrellHolmes-q3u หลายเดือนก่อน

    Walker Brenda Allen Matthew Hall Thomas

  • @markanesfreeman3642
    @markanesfreeman3642 16 วันที่ผ่านมา

    Thomas Nancy Jones Charles Johnson Ruth

  • @chan6565
    @chan6565 3 ปีที่แล้ว

    I hope you can answer my question, I chose logical drive and the disk image created is an unzippable zip file, and not in .001 format, is this normal?
    When I tried to unzip it, it says, format nor recognized/file damaged, and the second error there it says 0 archive.

  • @Игорь-ъ9е1и
    @Игорь-ъ9е1и 17 วันที่ผ่านมา

    Brown James Jackson Sharon Lee Brenda

  • @AdamDolores
    @AdamDolores 15 วันที่ผ่านมา

    4861 Kirsten Parkways

  • @mohammedbilal6226
    @mohammedbilal6226 3 ปีที่แล้ว +1

    Thankyou, great walk through.

  • @amitbaral7750
    @amitbaral7750 3 ปีที่แล้ว

    i want to file something from e01 image file. how can i do that? please any info?

  • @Teeleer
    @Teeleer 6 ปีที่แล้ว

    when i was creating an image for file types it created a winrar file for 001-2016 but after that it was 002, 003, etc, etc. why is that?

    • @DFIRScience
      @DFIRScience  4 ปีที่แล้ว +1

      Disk images can be split into parts. We do this so we do not have to have one very large file to work with and manage. The first part is often .001. The second part is .002, etc. The order is VERY important to ensure you put the image back together properly.

  • @playmangostingiu2217
    @playmangostingiu2217 2 ปีที่แล้ว

    Interesting video, I have just one doubt : mounting the usb disk in windows may cause the system itself to compromise the integrity of the content because of antivirus activity for instance, which can write or delete files without notify that. There is a way to create an image without mounting the usb disk volumes ? Thank yoy

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว +1

      Yes, you do not need to mount a drive to image it. When you plug a disk (or USB stick) into Windows, any partitions that Windows recognizes the file system will be mounted automatically. You can disable Windows automount from the command line with *dispart -> automount disable*
      BUT it is much safer (and standard practice) to use a hardware write blocker.
      th-cam.com/video/7eT8KSHMGFw/w-d-xo.html
      Tsurugi Linux also uses kernel-level software write blocking that works very well: tsurugi-linux.org

  • @johngrisum
    @johngrisum 11 หลายเดือนก่อน

    What write blocker did/do you use?

  • @D_Tech_And_Trek
    @D_Tech_And_Trek 5 ปีที่แล้ว

    Hi, How do I acquire a Disk (Virutal) Image of a Virtual Machine running using VMWare Workstation? Can I use FTK Imager - Creat Disk Image -> Physical Drive? Thank you.

  • @KeithRakowski
    @KeithRakowski 18 วันที่ผ่านมา

    924 Nitzsche Mission

  • @GreenGilbert-d6h
    @GreenGilbert-d6h 15 วันที่ผ่านมา

    359 Eldridge Rest

  • @SusanBeall-p6o
    @SusanBeall-p6o 10 วันที่ผ่านมา

    Davis Daniel Hernandez Anthony Brown Karen

  • @dubHE
    @dubHE 6 ปีที่แล้ว

    i have an ipod shuffle 1st generation. physically there is no damage to it, but it does not power on when plugged into charger or usb port in PC. is there any way for me to recover the songs from the ipod shuffle even tho the computer does not recognize it since it does not power on? please help any info would be greatly appreciated

  • @savannaholdridge8502
    @savannaholdridge8502 12 วันที่ผ่านมา

    1289 Jared Creek

  • @nigmaticz9995
    @nigmaticz9995 4 ปีที่แล้ว

    I am using Active@ to open the images but it just doesn't work. Can I not have just one .dd file image as opposed to so many 001 files?

    • @DFIRScience
      @DFIRScience  4 ปีที่แล้ว

      Yeah. You could just use one raw disk (dd) image instead of a multi-part image. However, most raw images are very big, so it's normal to split them. Either will work.

  • @tarikeltaeib9663
    @tarikeltaeib9663 4 ปีที่แล้ว

    I would like to have this data USB , can I ?

  • @JibonKhan-v5l
    @JibonKhan-v5l 22 วันที่ผ่านมา

    Collier Rapids

  • @samirowan9590
    @samirowan9590 2 หลายเดือนก่อน

    That was brilliant. Thanks men

  • @HumeAdair-r2p
    @HumeAdair-r2p 22 วันที่ผ่านมา

    Marquis Land

  • @PrivateYouTubeE
    @PrivateYouTubeE 4 ปีที่แล้ว +1

    Thank you for this thorough walk through!

  • @PaigeAddison-e5f
    @PaigeAddison-e5f 19 วันที่ผ่านมา

    Jameson Rest

  • @RobertCrosby-v4u
    @RobertCrosby-v4u 12 วันที่ผ่านมา

    Bethel Club

  • @HelenVoss-i1r
    @HelenVoss-i1r 21 วันที่ผ่านมา

    Gladys Dale

  • @KyleUrbas-z5c
    @KyleUrbas-z5c 20 วันที่ผ่านมา

    Mraz Pine

  • @PattieKaplan-d1h
    @PattieKaplan-d1h 28 วันที่ผ่านมา

    Elva Estates

  • @miss_tech
    @miss_tech 2 ปีที่แล้ว

    Why are you choosing the ftk imager software ?

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว

      Because it works well, it does quite a lot with just a few options, and it's free. I tend to use Guymager in Linux more often, but if you want a tool that can do great imaging and some basic analysis, FTK Imager is very nice.

  • @MrBlorra
    @MrBlorra 3 ปีที่แล้ว

    Think you explained half a year of education, really good!

  • @FernandaVannatten-f9h
    @FernandaVannatten-f9h หลายเดือนก่อน

    Emmanuel Spurs

  • @sameddemir2583
    @sameddemir2583 6 ปีที่แล้ว

    Hello bro,Good job thx :)

  • @mikemeetstec
    @mikemeetstec 2 ปีที่แล้ว

    Man's voice is so smooth. What mic are you using?

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว

      That was a Sony ecm-ms907 with a generic pre-amp. Noise reduction with Audacity (www.audacityteam.org/). I think you can get the same or better quality with a Rode NT-USB (amzn.to/3b3pjQk) without the pre-amp and doesn't require a battery!

  • @ElouiseYazzie-r6j
    @ElouiseYazzie-r6j 20 วันที่ผ่านมา

    Simonis Shores

  • @SurinderSingh-mr9ey
    @SurinderSingh-mr9ey 5 ปีที่แล้ว

    Thanks for this informative video.
    I am trying to prepare an image from 10 MB logical drive but FTKImager is asking for around 95 GB free storage space.
    Why such large memory space is required?
    Thanks in anticipation for your response....

    • @DFIRScience
      @DFIRScience  4 ปีที่แล้ว +1

      The only thing I can think is that you have a 10MB partition, but you are selecting physical disk imaging so it will get the whole 95GB disk. You want a logical disk/partition image it seems.

  • @amaniyousri6174
    @amaniyousri6174 4 ปีที่แล้ว

    I need your help in one of my micromaster course pls Answer me

  • @miss_tech
    @miss_tech 2 ปีที่แล้ว

    Xtreamly eazy

  • @stevestruthers5096
    @stevestruthers5096 6 ปีที่แล้ว

    Great Video, great explanation, thank you so much !!!

  • @humanlife3
    @humanlife3 7 หลายเดือนก่อน

    Thankyou

  • @lovidyahelmi5937
    @lovidyahelmi5937 7 ปีที่แล้ว

    thank you so much for sharing, i really need this!

  • @izzy2937
    @izzy2937 2 ปีที่แล้ว

    Hey how do I open and read the copy?

    • @DFIRScience
      @DFIRScience  2 ปีที่แล้ว

      Once you create a disk image it is an "exact copy" of the original. You will need to use a program like Autopsy to view the disk contents - www.autopsy.com/

  • @h7ndrik
    @h7ndrik 7 ปีที่แล้ว

    This is so helpful and well explained.

  • @VivienTrame-x3x
    @VivienTrame-x3x 17 วันที่ผ่านมา

    Barton Estates

  • @advancestockinventorymanag9585
    @advancestockinventorymanag9585 6 ปีที่แล้ว

    Sir how to open the images that we have created?

    • @DFIRScience
      @DFIRScience  6 ปีที่แล้ว +2

      Once you create a disk image you can use disk management tools to do whatever you need. For forensics, one of the easiest ways to analyze the disk for free is with Autopsy: www.autopsy.com/download/

  • @BoswellIrene-f3b
    @BoswellIrene-f3b 12 วันที่ผ่านมา

    Hollie Groves

  • @akhilowle1
    @akhilowle1 7 ปีที่แล้ว

    Thanks very much

  • @MrFarkad08
    @MrFarkad08 7 ปีที่แล้ว

    Thanks a lot....

  • @harisnsiddiqui
    @harisnsiddiqui 7 ปีที่แล้ว

    Neatly done.

  • @AnnetteMontgomery-k8t
    @AnnetteMontgomery-k8t หลายเดือนก่อน

    Gonzalez Paul White Larry Lewis Donald

  • @LorenzoWesler-t4n
    @LorenzoWesler-t4n 3 วันที่ผ่านมา

    Mann Turnpike