At roughly the cost of the power your machine is using, Autopsy is a smart forensics tool. Autopsy has some filtering capabilities that allows the user to view hidden and deleted files and well as sorting file type capabilities which make finding a particular file type much easier. Working with a forensics image, you can follow the same steps with the image that you’ll have previously mounted as an Item on FTK Imager (or Imager Lite if you prefer).
However, after some minor adjustments to the image viewing configuration I was able to view an image easily. Autopsy was a little difficult to get going initially if you are not a native Linux user. Although I only used the free version, I can image the commercial enterprise edition is a much stronger tool at a cost. With the easy to navigate graphical user interface, the user can view hidden files and folders, view pictures, see deleted files, view hex mode of files, and capture memory to name a few. I found using FTK imager lite was surprisingly straight forward. You do not have the required permissions to view the files attached to this post. It helps you to search for various artifacts of a users online activities like chatting, surfing, emailing.
#Download Ftk Imager Lite Free download zip#
This was my first encounter with using a data forensics tool, so I found this extremely interesting. Download ZIP FTK Imager Lite (or may be just FTK Imager (exe) and then extract, but what if FTK Imager cant be extract, or not free, or not portable, i dont know, i not trying) Portable (i hope), but not stealth HKEYCURRENTUSERSoftwareAccessData - may be more (WinXP). Ftk Imager Software - Free Download Ftk Imager Ftk Imager Software Belkasoft Forensic Carver v.2.0 Build 147 Belkasoft Forensic Carver allows for retrieving deleted information from hard drives and analyzing Live RAM in memory dumps. A Comparison of Autopsy and Access Data’s Forensic Tool Kit (FTK)