Skip to content

FTK Imager

What FTK Imager does

Forensic acquisition and preview

FTK Imager is a Windows forensic acquisition and preview utility. It can create physical or logical images, preview supported evidence sources, export selected files and verify acquired images without requiring a full FTK installation.

Guide scope

This guide uses FTK Imager to create a logical E01 image in an authorised training environment. The original installation and imaging screenshots remain in their procedural pages.

Protect the source

Use disposable training media or an explicitly authorised source. Apply an appropriate write-protection method where required, record unavoidable live-system changes, and never use the source volume as the destination.

Choose your journey

Evidence workflow

1Authorise2Protect source3Acquire image4Verify output5Preserve evidence
  • Authorise: Record the case question and identify the exact source.
  • Protect: Document write protection and keep output away from the source.
  • Acquire: Select the proportionate image type and retain the settings used.
  • Verify: Compare recorded hashes and review the acquisition log and errors.
  • Preserve: Protect the image, log and context; analyse a verified working copy.

Before you begin

  • Source
    A small disposable training drive, volume or supplied image.
  • Destination
    A separate controlled volume with sufficient free space.
  • Record
    Tool version, source identity, case reference, time, settings, hashes and errors.

What the result can support

Supported conclusion

FTK Imager can demonstrate what was acquired, which settings were used and whether recorded verification values agree.

Interpretation limit

A successful acquisition does not by itself establish user intent, authorship or that every relevant source was available.