FTK Imager - Forensic Acquisition Tool - FTK Imager Tutorial - FTK Image Loading Analysis

  Рет қаралды 74,778

Free Education Academy - FreeEduHub

Free Education Academy - FreeEduHub

Күн бұрын

Пікірлер: 47
@coachluisms
@coachluisms 2 жыл бұрын
That is the best video explanation I have found on FTK. Thank you for the attention to detail.
@FreeEduHub
@FreeEduHub 2 жыл бұрын
Glad it was helpful! Thanks for visiting
@banksinfo5063
@banksinfo5063 Жыл бұрын
Sir, this is to much informative and practical video. I will request you that please add mobile forensic, audio video forensic, image forensic and others related to digital forensic .. Your wording style is impressive because its easy to understand ..
@FreeEduHub
@FreeEduHub Жыл бұрын
thanks for the feedback We are starting new course on Cloud Computing / Network Security & Penetration Testing soon You will find lots of new stuff weekly :)
@banksinfo5063
@banksinfo5063 Жыл бұрын
@@FreeEduHub In Sha Allah .. May Allah bless you and keep it up..
@rajaarya117
@rajaarya117 6 ай бұрын
My old mobile device not detected in ftk imager physical disk. What to do now..
@FreeEduHub
@FreeEduHub 6 ай бұрын
look for its related plugins
@er.tariqalamfarooqi4771
@er.tariqalamfarooqi4771 Жыл бұрын
Thnx for the information. Can we do work from home in ftk imager in jobs?
@FreeEduHub
@FreeEduHub Жыл бұрын
its best to try at home on your usb and harddrives
@emmanuelswealth9377
@emmanuelswealth9377 Жыл бұрын
Good video full of knowledge . Thank you. Please sir I like it if you make a video of FTK Image and dd in Ubuntu inside VMware work station
@FreeEduHub
@FreeEduHub Жыл бұрын
Sure I will
@ikhsansdq
@ikhsansdq 10 ай бұрын
Hi, thanks for sharing the video, great explanation btw but why my .001 extension is TXT?
@FreeEduHub
@FreeEduHub 10 ай бұрын
thats a default behavior
@ikhsansdq
@ikhsansdq 10 ай бұрын
@@FreeEduHub Yes, but my FTK imager didn't generate the other .001 other than the txt to be mounted in the FTK imager later on, instead it generate a ZIP folder, do you know about this problem on how to solved this issue?
@FreeEduHub
@FreeEduHub 10 ай бұрын
check file format settings in FTK Imager, it should generate .E01 or DD or RAW files etc Manually open the file .TXT file with FTK Imager as it seems like file association issue Did you check if there is anything in the zip file?
@ikhsansdq
@ikhsansdq 10 ай бұрын
@@FreeEduHub so apparently inside the zip file there is another file with size of almost 30gb called 001_Evidences (which is my name format settins), and when I try to mount it, turns out it's the .001 file but in zip file, yet still I can't mount it
@FreeEduHub
@FreeEduHub 10 ай бұрын
try OSFMount to mount and check, further 001 indicates there will be other sequenced files also
@pandey7549
@pandey7549 Жыл бұрын
Sir by using this software can we tell that what is the origin of any photo or video
@FreeEduHub
@FreeEduHub Жыл бұрын
you can know the details when it was saved or created To know origin of the photo, you will have to drill down forensics of image / video itself you will get recording date and camera etc
@rakshithyadav6894
@rakshithyadav6894 2 жыл бұрын
Hi I have a question Can we connect laptop hard disk as secondary HDD to system and take aquire the image of that Is this possible
@FreeEduHub
@FreeEduHub 2 жыл бұрын
yes you can, make sure you lock the harddisk first so that the contents are not changed
@Yadav-it3ku
@Yadav-it3ku Жыл бұрын
Sir I'm facing a problem in imaging a pendrive. Every time when I try to image the pendrive like that you did in the above video, everytime I found ubd_drive.001 to be a WinRar archive file. Can you please suggest me what to do now...
@FreeEduHub
@FreeEduHub Жыл бұрын
it will create several 001 002 003 files etc. Its normal
@tahahasan4636
@tahahasan4636 11 ай бұрын
But sir it's not creating me any new disk ! I had the same problem !
@123gregery
@123gregery Жыл бұрын
That was very good. Thank you
@FreeEduHub
@FreeEduHub Жыл бұрын
Glad you enjoyed it!
@listentopapi
@listentopapi 7 ай бұрын
I keep getting the BSOD as soon as I actually run the memory dump feature. Is there a fix for this issue?
@FreeEduHub
@FreeEduHub 7 ай бұрын
resources issue on your host computer
@josemanuelcordovavillanuev4593
@josemanuelcordovavillanuev4593 10 ай бұрын
I have a image, if i mount it i can see the file that come from the DVD, but if i wan to export it i cant select a file because no one apear in the "Evience Tree"
@josemanuelcordovavillanuev4593
@josemanuelcordovavillanuev4593 10 ай бұрын
And the Directory listing expor does not have the file in the DVD but i can see it in the logical drive that was mounted! ¿?
@FreeEduHub
@FreeEduHub 10 ай бұрын
it could be due to multiple issues from version to hidden files, health, permissions and how is it exported
@samael1981
@samael1981 2 жыл бұрын
How do you look for data if it's only being showed in hexadecimal form? Let's say I am looking for a document that was deleted, I can only see the contents in hexadecimal form, so how would I be able to find it without using autopsy browser or some other additional software?
@FreeEduHub
@FreeEduHub 2 жыл бұрын
We usually use HEX to ASCII converters. For recovery of documents etc you can use Recuva free version, it would show you content of the files and recovery process Software like FTK are used for forensics analysis by professionals where the hash code of it is more important than the data in those documents
@samael1981
@samael1981 2 жыл бұрын
@@FreeEduHub So for example if I want to prove that somebody downloaded a classified document on their computer that they shouldn't have and then subsequently deleted it, I would just use FTK imager, locate the image of that document in unallocated space, then the once I find the document, compare the hashes of that item found to the hash of the actual document? I wouldn't actually recover the human readable contents of the document itself?
@FreeEduHub
@FreeEduHub 2 жыл бұрын
@@samael1981 You can even recover the entire document Whatever you do make sure you image the entire system first and then work on the image But its recoverable
@samael1981
@samael1981 2 жыл бұрын
@@FreeEduHub One last question. Would I recover the entire document in human readable format using FTK or would I need a third party program like Autopsy or Recuva?
@FreeEduHub
@FreeEduHub 2 жыл бұрын
@@samael1981 It has plugins and ad-ons to be added which are not free So if a free software works, use it
@overlordo2293
@overlordo2293 3 жыл бұрын
Thank you
@FreeEduHub
@FreeEduHub 3 жыл бұрын
You're welcome
@dongodilorica6037
@dongodilorica6037 Жыл бұрын
Thank you Sir!! 💯💪
@FreeEduHub
@FreeEduHub Жыл бұрын
Very welcome
@hma20008
@hma20008 5 ай бұрын
how to recover the deleted one?
@FreeEduHub
@FreeEduHub 5 ай бұрын
i am showing how to recover deleted files from USB and HDD
@ppnsperikanansangihe
@ppnsperikanansangihe 4 ай бұрын
Thnaks
@FreeEduHub
@FreeEduHub 4 ай бұрын
you are most welcome
@finajulfiana2298
@finajulfiana2298 Жыл бұрын
How about Android file deleted?
@FreeEduHub
@FreeEduHub Жыл бұрын
there are different tools for android
Forensic Acquisition in Windows - FTK Imager
29:03
DFIRScience
Рет қаралды 164 М.
Autopsy - Forensic Acquisition Tool  | Digital Forensics Investigation | Autopsy Tutorial
23:17
Free Education Academy - FreeEduHub
Рет қаралды 91 М.
REAL 3D brush can draw grass Life Hack #shorts #lifehacks
00:42
MrMaximus
Рет қаралды 6 МЛН
Officer Rabbit is so bad. He made Luffy deaf. #funny #supersiblings #comedy
00:18
Funny superhero siblings
Рет қаралды 18 МЛН
«Кім тапқыр?» бағдарламасы
00:16
Balapan TV
Рет қаралды 254 М.
How to make a Forensic Image with FTK Imager
11:04
DFIR Noob
Рет қаралды 27 М.
Disk Analysis with Autopsy | HackerSploit Blue Team Training
52:45
Akamai Developer
Рет қаралды 17 М.
Live Forensic RAM analysis Windows 10 - FTK Imager - Extract and recover jpeg picture file from RAM.
7:24
CyDig Cyber Security Digital Forensics Education
Рет қаралды 3,8 М.
Starting a New Digital Forensic Investigation Case in Autopsy 4.19+
38:59
Storage Media Life Expectancy: SSDs, HDDs & More!
18:18
ExplainingComputers
Рет қаралды 450 М.
Forensic Data Acquisition - Hardware Write Blockers
8:00
DFIRScience
Рет қаралды 54 М.
18 Weird and Wonderful ways I use Docker
26:18
NetworkChuck
Рет қаралды 286 М.
NTFS Master File Table (MFT) Explained: Extract Recover Files from Resident & Non-Resident Data
25:49
CyDig Cyber Security Digital Forensics Education
Рет қаралды 5 М.
ProDiscover Tutorial | Forensic Acquisition Tool | ProDiscover Digital forensics
12:14
Free Education Academy - FreeEduHub
Рет қаралды 7 М.
REAL 3D brush can draw grass Life Hack #shorts #lifehacks
00:42
MrMaximus
Рет қаралды 6 МЛН