Forensic Acquisition in Windows - FTK Imager

Поділитися
Вставка
  • Опубліковано 24 січ 2025

КОМЕНТАРІ • 65

  • @nicholasedwardsillett1259
    @nicholasedwardsillett1259 3 роки тому +5

    I have an assessment due tonight and this helped me a lot. Thank you so much

  • @charlesbergvi6705
    @charlesbergvi6705 3 роки тому +3

    I cant stress enough how much this has helped for my upcoming assignment, prime content my friend, thankyou...

    • @DFIRScience
      @DFIRScience  3 роки тому +2

      Glad to hear it. Let me know if you need videos on any other topics!

  • @TheMrmuaz
    @TheMrmuaz 3 роки тому +3

    Well that's a really clear explanation, thank you.

  • @MrBlorra
    @MrBlorra 3 роки тому

    Think you explained half a year of education, really good!

  • @harinandan6557
    @harinandan6557 3 місяці тому +1

    Hey i am struggling to do the image thing where it’s downloading but it’s taking too much of the space and later saying failure this is for an assignment I don’t know why it’s taking 1 million mb or kb and failing the process so could you explain please?

  • @PrivateYouTubeE
    @PrivateYouTubeE 4 роки тому +1

    Thank you for this thorough walk through!

  • @sahenders1
    @sahenders1 4 роки тому +1

    Well done! Thank you for such a detailed demonstration.

  • @madhuraneniyashwanth5739
    @madhuraneniyashwanth5739 2 роки тому

    This is so helpful and clear detailed explanation ,thank you so much

  • @samirowan9590
    @samirowan9590 6 місяців тому

    That was brilliant. Thanks men

  • @mohammedbilal6226
    @mohammedbilal6226 4 роки тому +1

    Thankyou, great walk through.

  • @h7ndrik
    @h7ndrik 7 років тому

    This is so helpful and well explained.

  • @stevestruthers5096
    @stevestruthers5096 7 років тому

    Great Video, great explanation, thank you so much !!!

  • @johngrisum
    @johngrisum Рік тому

    What write blocker did/do you use?

  • @chan6565
    @chan6565 4 роки тому

    I hope you can answer my question, I chose logical drive and the disk image created is an unzippable zip file, and not in .001 format, is this normal?
    When I tried to unzip it, it says, format nor recognized/file damaged, and the second error there it says 0 archive.

  • @lovidyahelmi5937
    @lovidyahelmi5937 7 років тому

    thank you so much for sharing, i really need this!

  • @D_Tech_And_Trek
    @D_Tech_And_Trek 6 років тому

    Hi, How do I acquire a Disk (Virutal) Image of a Virtual Machine running using VMWare Workstation? Can I use FTK Imager - Creat Disk Image -> Physical Drive? Thank you.

  • @amitbaral7750
    @amitbaral7750 3 роки тому

    i want to file something from e01 image file. how can i do that? please any info?

  • @izzy2937
    @izzy2937 2 роки тому +1

    Hey how do I open and read the copy?

    • @DFIRScience
      @DFIRScience  2 роки тому

      Once you create a disk image it is an "exact copy" of the original. You will need to use a program like Autopsy to view the disk contents - www.autopsy.com/

  • @playmangostingiu2217
    @playmangostingiu2217 2 роки тому

    Interesting video, I have just one doubt : mounting the usb disk in windows may cause the system itself to compromise the integrity of the content because of antivirus activity for instance, which can write or delete files without notify that. There is a way to create an image without mounting the usb disk volumes ? Thank yoy

    • @DFIRScience
      @DFIRScience  2 роки тому +1

      Yes, you do not need to mount a drive to image it. When you plug a disk (or USB stick) into Windows, any partitions that Windows recognizes the file system will be mounted automatically. You can disable Windows automount from the command line with *dispart -> automount disable*
      BUT it is much safer (and standard practice) to use a hardware write blocker.
      ua-cam.com/video/7eT8KSHMGFw/v-deo.html
      Tsurugi Linux also uses kernel-level software write blocking that works very well: tsurugi-linux.org

  • @harisnsiddiqui
    @harisnsiddiqui 7 років тому

    Neatly done.

  • @mikemeetstec
    @mikemeetstec 2 роки тому

    Man's voice is so smooth. What mic are you using?

    • @DFIRScience
      @DFIRScience  2 роки тому

      That was a Sony ecm-ms907 with a generic pre-amp. Noise reduction with Audacity (www.audacityteam.org/). I think you can get the same or better quality with a Rode NT-USB (amzn.to/3b3pjQk) without the pre-amp and doesn't require a battery!

  • @dubHE
    @dubHE 7 років тому

    i have an ipod shuffle 1st generation. physically there is no damage to it, but it does not power on when plugged into charger or usb port in PC. is there any way for me to recover the songs from the ipod shuffle even tho the computer does not recognize it since it does not power on? please help any info would be greatly appreciated

    • @AnthonyNelms-nh8ko
      @AnthonyNelms-nh8ko 2 місяці тому

      Did you ever get any help?

    • @dubHE
      @dubHE 2 місяці тому

      @AnthonyNelms-nh8ko negative

  • @nigmaticz9995
    @nigmaticz9995 5 років тому

    I am using Active@ to open the images but it just doesn't work. Can I not have just one .dd file image as opposed to so many 001 files?

    • @DFIRScience
      @DFIRScience  5 років тому

      Yeah. You could just use one raw disk (dd) image instead of a multi-part image. However, most raw images are very big, so it's normal to split them. Either will work.

  • @Teeleer
    @Teeleer 6 років тому

    when i was creating an image for file types it created a winrar file for 001-2016 but after that it was 002, 003, etc, etc. why is that?

    • @DFIRScience
      @DFIRScience  5 років тому +1

      Disk images can be split into parts. We do this so we do not have to have one very large file to work with and manage. The first part is often .001. The second part is .002, etc. The order is VERY important to ensure you put the image back together properly.

  • @miss_tech
    @miss_tech 2 роки тому

    Why are you choosing the ftk imager software ?

    • @DFIRScience
      @DFIRScience  2 роки тому

      Because it works well, it does quite a lot with just a few options, and it's free. I tend to use Guymager in Linux more often, but if you want a tool that can do great imaging and some basic analysis, FTK Imager is very nice.

  • @sylviagardner6243
    @sylviagardner6243 3 місяці тому +1

    69475 Joel Extensions

  • @ElouiseYazzie-r6j
    @ElouiseYazzie-r6j 4 місяці тому +1

    Simonis Shores

  • @tarikeltaeib9663
    @tarikeltaeib9663 4 роки тому

    I would like to have this data USB , can I ?

  • @SurinderSingh-mr9ey
    @SurinderSingh-mr9ey 6 років тому

    Thanks for this informative video.
    I am trying to prepare an image from 10 MB logical drive but FTKImager is asking for around 95 GB free storage space.
    Why such large memory space is required?
    Thanks in anticipation for your response....

    • @DFIRScience
      @DFIRScience  5 років тому +1

      The only thing I can think is that you have a 10MB partition, but you are selecting physical disk imaging so it will get the whole 95GB disk. You want a logical disk/partition image it seems.

  • @JibonKhan-v5l
    @JibonKhan-v5l 4 місяці тому +1

    Collier Rapids

  • @akhilowle1
    @akhilowle1 7 років тому

    Thanks very much

  • @AdamDolores
    @AdamDolores 4 місяці тому +1

    4861 Kirsten Parkways

  • @sameetdmrr
    @sameetdmrr 6 років тому

    Hello bro,Good job thx :)

  • @BoswellIrene-f3b
    @BoswellIrene-f3b 4 місяці тому +1

    Hollie Groves

  • @advancestockinventorymanag9585
    @advancestockinventorymanag9585 6 років тому

    Sir how to open the images that we have created?

    • @DFIRScience
      @DFIRScience  6 років тому +2

      Once you create a disk image you can use disk management tools to do whatever you need. For forensics, one of the easiest ways to analyze the disk for free is with Autopsy: www.autopsy.com/download/

  • @JoeMuster-t3h
    @JoeMuster-t3h 3 місяці тому +1

    William Islands

  • @amaniyousri6174
    @amaniyousri6174 4 роки тому

    I need your help in one of my micromaster course pls Answer me

  • @VivienTrame-x3x
    @VivienTrame-x3x 4 місяці тому +1

    Barton Estates

  • @MrFarkad08
    @MrFarkad08 7 років тому

    Thanks a lot....

  • @humanlife3
    @humanlife3 11 місяців тому

    Thankyou

  • @savannaholdridge8502
    @savannaholdridge8502 4 місяці тому +1

    1289 Jared Creek

  • @LorenzoWesler-t4n
    @LorenzoWesler-t4n 3 місяці тому +1

    Mann Turnpike

  • @HumeAdair-r2p
    @HumeAdair-r2p 4 місяці тому +1

    Marquis Land

  • @FernandaVannatten-f9h
    @FernandaVannatten-f9h 4 місяці тому +1

    Emmanuel Spurs

  • @KyleUrbas-z5c
    @KyleUrbas-z5c 4 місяці тому +1

    Mraz Pine

  • @miss_tech
    @miss_tech 2 роки тому

    Xtreamly eazy

  • @DoraSpring-m9o
    @DoraSpring-m9o 4 місяці тому +1

    Harris Dorothy Clark Mary Anderson Eric

  • @RobertCrosby-v4u
    @RobertCrosby-v4u 4 місяці тому +1

    Bethel Club

  • @DarrellHolmes-q3u
    @DarrellHolmes-q3u 5 місяців тому

    Walker Brenda Allen Matthew Hall Thomas