FTK Imager Hands-on Labs¶
Choose a lab¶
Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
How to use these labs
Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.
Interactive Lab¶
FTK Imager Interactive Lab
Practise a guided FTK Imager workflow in a safe browser simulation with immediate feedback.
Exterro FTK Imager 4.7.3.81Case SUSA-041 · training simulation− □ ×D:\SUSA-041\Images. Record the source, destination, format and verification result.- 1Evidence type
- 2Source
- 3Image type
- 4Destination
- 5Verify
Select the source evidence type
The case asks for one accessible training volume, not a sector-level image of the whole device.
Choose the authorised source
Choose the destination image format
The evidence package requires compression, case metadata and embedded verification values.
Configure the controlled destination
Review the acquisition evidence
- Source
- E:\ [TRAINING-USB]
- Format
- E01
- Destination
- Verification
- SHA-256 acquisition and verification values match
- Read errors
- 0
Computed hash : 69d94d2e...b97a
Verify hash : 69d94d2e...b97a
Result : VERIFIED
Full Lab¶
FTK Imager Full Lab
Hands-on DFIR proof of concept
Prepare it. Examine it. Explain it.
Use FTK Imager to create and verify a small forensic image without writing to the source, retain the evidence trail and write a bounded finding another analyst can review.
Safety boundary
Use training media and appropriate write protection. Never practise acquisition on irreplaceable source evidence.
a disposable training disk or supplied forensic-image source and adequate destination storage
an acquisition log and image with recorded verification hashes and source details
Recommended first
Beginner Core Lab¶
Complete one bounded FTK Imager workflow using the documented source, settings and expected result.
Optional extension
Add a comparison¶
After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.
Full Lab scenario¶
You are the first analyst reviewing a bounded training case. Your task is to create and verify a small forensic image without writing to the source. The result must be understandable to a second analyst who did not watch you perform the work.
01
Activity 1: Prepare the environment¶
- Record the case question, authority and the identity of the isolated training system or evidence source.
- Record the FTK Imager version, provenance, system time and time zone.
- Identify the original material, working location and separate output destination. Confirm that there is enough free space.
- Take or verify a recoverable baseline before changing the training system.
02
Activity 2: Complete the focused task¶
- Restate the investigation question and select only the settings or commands required to create and verify a small forensic image without writing to the source.
- Follow the preserved FTK Imager guide and record any necessary difference in paths, labels or version-specific behaviour.
- Record start and finish times, relevant settings, completion status, warnings and errors.
- Preserve the returned output and keep it attributable to its source and collection context.
03
Activity 3: Review and report¶
- Work from an identified copy and confirm an acquisition log and image with recorded verification hashes and source details.
- Separate direct tool observations from analyst interpretation. Record missing fields, unavailable material and alternative explanations.
- Preserve relevant integrity information, settings or commands and the evidence needed for another analyst to reproduce the result.
- Write a bounded conclusion with observation, interpretation, confidence and limitations, then clean up the disposable environment.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.
-
Core completion¶
Required to demonstrate a safe, attributable workflow.
-
Good analyst practice¶
Supplementary records that improve reproducibility and review quality.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.