Forensic Toolkit (FTK) logo

Forensic Toolkit (FTK)

by AccessData now part of Exterro · Since 1987
No reviews yet
ActiveAvailable globallyCloud
Quick facts
VendorAccessData now part of Exterro
Year launched1987
StatusActive
Location2175 NW Raleigh St. Suite 110 Portland, OR 97210
Countries servedGlobal
Languages12
Integrations
Free tier
Free trial
Contact salesYES

About Forensic Toolkit (FTK)

Forensic Toolkit (FTK) is a digital forensics software from AccessData now part of Exterro that enables investigators to analyze digital evidence. It provides features such as data carving, email analysis, and file signature analysis so users can efficiently recover and examine critical data. FTK allows for thorough investigation of electronic evidence while supporting various data sources. It is designed to assist law enforcement and private investigators in uncovering vital information in criminal and civil cases. Key capabilities: data carving email analysis file signature analysis automated reporting user-friendly interface Best for: forensic investigators that need to analyze digital evidence for legal proceedings.

Forensic Toolkit (FTK) by AccessData, now part of Exterro, stands as one of the most comprehensive and respected digital forensics tools in the industry. Designed to support law enforcement agencies, forensic investigators, legal teams, cybersecurity compliance officers, and corporate IT departments, FTK serves as a powerful solution for processing and analyzing digital evidence. Its primary purpose is to streamline digital investigations by offering a centralized platform for data collection, processing, indexing, searching, and visualization. Key features include robust indexing capabilities, automated evidence processing, powerful decryption, and an advanced visualization engine that helps users quickly interpret large and complex datasets. The user interface of FTK is professional and detail-oriented, tailored for users who are already familiar with digital forensic workflows. While it may appear dense for beginners, it is laid out logically with clearly defined tabs and a dashboard that centralizes core functions. The workspace allows investigators to easily manage case files, view file systems, analyze email data, and examine deleted files. FTK uses a pane-based view that enables users to cross-reference evidence from different data types in a single session.

Pros & Cons

What users like
  • +Comprehensive: Collects and analyzes evidence from computers, mobiles, and cloud.
  • +Fast & Efficient: Speeds up investigations with pre-processing and advanced tools.
  • +Powerful Recovery: Finds hidden, deleted, or encrypted data.
  • +User-Friendly: Intuitive interface for all skill levels.
  • +Defensible: Produces reliable evidence for legal use.
What users flag
  • Complexity: Despite user-friendly aspects, deep forensic analysis still requires expertise.
  • Resource Intensive: Processing large datasets can demand significant computing power.
  • Focus: Primarily a forensic tool, not for general data recovery or IT management.

Features

Key features

Comprehensive Digital Evidence Collection & Processing
Offers robust capabilities for full-disk image collection and efficiently processing and indexing a wide range of digital evidence upfront, including data from computers, mobile devices, and cloud apps, to enable faster analysis.
Rapid & Efficient Investigation
Designed to streamline forensic investigations by quickly pointing investigators to relevant artifacts, narrowing the scope, and reducing the time to close cases through its powerful processing engine and advanced searching/filtering.
Intuitive User Interface
Features an intuitive interface that makes it easier for both experienced investigators and non-technical users to navigate, significantly reducing the learning curve.
Advanced Artifact & Data Recovery
Excels at finding more data artifacts (e.g., categorizing and displaying various data types, parsing registry files, carving data to recover deleted evidence) and includes capabilities like decrypting files and cracking passwords to uncover hidden information.
Integrated Mobile & Mac Data Review
Supports the processing and analysis of mobile device extractions (from tools like Cellebrite, Oxygen, XRY, GrayKey) and Apple file systems (Mac data), allowing investigators to find connections across diverse data sources in a single database.
Multimedia & Image Analysis
Provides features like Multimedia Thumbnail Review for effortless pivoting through images/videos, along with facial and object recognition and integration with collaborative hash databases (e.g., Project Vic, CAID UK) for faster identification in sensitive cases (e.g., CSAM).
Defensible & Repeatable Process
Emphasizes a forensically sound approach to ensure the integrity of evidence throughout the investigation, making findings reliable and admissible in court.

Additional features

Comprehensive Digital Evidence Collection
Facilitates defensible full-disk image collection and supports collecting data from various sources including computers, mobile devices, and cloud applications.
Powerful & Scalable Processing Engine
Features a reliable, multi-threaded processing engine that efficiently processes and indexes large volumes of digital evidence upfront, accelerating subsequent analysis and review.
Intuitive User Interface
Designed with an intuitive interface that reduces the learning curve, making the software accessible and efficient for both experienced forensic investigators and less technical users.
Advanced Artifact & Data Recovery
Capable of intelligently categorizing and displaying a vast array of data artifacts, performing data carving to recover deleted evidence, decrypting encrypted files, and cracking passwords from over 100 applications to uncover hidden information.
Fast & Efficient Evidence Searching
Enables rapid filtering and searching of evidence, as data is processed and indexed upfront, eliminating wait times during the review phase.
Integrated Mobile Data Processing
Supports parsing native unprocessed UFD extractions from various mobile devices (e.g., Cellebrite, Oxygen, XRY, GrayKey) and allows for the review of chat messages from popular apps (Twitter, WhatsApp) in a near-native view within a single database.
Mac Data Review & Analysis
Provides capabilities to process and analyze datasets containing Apple file systems (even if encrypted, compressed, or deleted), parsing various Mac artifacts like Apple Mail, iMessage, Safari browser data, and system summary data (Spotlight Search, KnowledgeC, Power Log data).
Multimedia Thumbnail Review
Offers an efficient way to pivot through image and video case evidence using interactive thumbnails, allowing for easy inspection, labeling, and categorization with context-providing mini timelines of user activity.
Image Identification & Categorization
Utilizes facial and object recognition to automatically locate similar images and integrates with collaborative hash databases like Project Vic and CAID UK to assist in identifying victims, particularly in CSAM investigations.
Registry File Parsing (System Summary)
Automatically parses Windows registry files to reconstruct user activity timelines, showing every application opened, internet activity, network connections, and associated timestamps.
Memory Analysis
Includes a module for analyzing dumped memory data, allowing investigators to identify hidden processes, enumerate running processes, associated DLLs, network sockets, and open handles.
Portable Case Export
Allows for exporting selected data into a portable case for offline review by non-FTK users (detectives, analysts, attorneys), with labels and bookmarks syncing back to the original case.
Defensible Reporting
Facilitates the generation of detailed and defensible reports in various formats (PDF, HTML, XML, RTF) suitable for legal proceedings, with the ability to bookmark key evidence.
Custom Scripting & Automation
Supports the creation and execution of custom Python scripts for tailored analysis and automation of forensic tasks.
Investigator Wellness Settings
Includes features designed to reduce repeated exposure to sensitive content in investigations, particularly in cases involving child sexual abuse material (CSAM).
Robust Database-Driven Architecture
Ensures that work is not lost due to crashes, as all data is stored in a resilient database, providing stability unlike memory-based tools.
Remote Endpoint Imaging
Can image a remote endpoint over a network (typically an FTK Enterprise feature) for collection from live systems.
Hash Function Support
Provides various hash functions for data integrity verification.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

Global
Countries served
12
Interface languages
6
Billing currencies

Interface languages

EnglishSpanishFrenchGermanPortugueseChineseJapaneseKoreanRussianItalianDutchTurkish

Billing currencies

🇺🇸USD🇪🇺EUR🇬🇧GBP🇦🇺AUD🇨🇦CAD🇯🇵JPY

No reviews yet

Be the first to drop a review

Alternatives to Forensic Toolkit (FTK)

EnCase Forensic logo

EnCase Forensic

EnCase Forensic is a digital forensic software from Opentext that enables investigators to gather digital…

FARO Zone 3D (FARO.com) logo

FARO Zone 3D (FARO.com)

FARO Zone 3D is a forensic visualization software from FARO that supports the analysis, reconstruction,…

Autopsy logo

Autopsy

Autopsy is a digital forensics software from Sleuth Kit Labs that provides a comprehensive open-source…

S

SceneWorks

SceneWorks is a software platform from SpheronVR that focuses on creating immersive virtual reality experiences.…

P

Phonexia Orbis Investigator

Phonexia Orbis Investigator is a forensic audio analysis software from Phonexia that provides tools for…

Forensic Explorer logo

Forensic Explorer

Forensic Explorer is a forensic analysis software from GetData Forensics that focuses on analyzing computer…

Often compared with Forensic Toolkit (FTK)

Compare any two tools →
EnCase Forensic logo
EnCase Forensic
Digital Forensics
0.0
FARO Zone 3D (FARO.com) logo
FARO Zone 3D (FARO.com)
Digital Forensics
0.0
Autopsy logo
Autopsy
Digital Forensics
0.0
S
SceneWorks
Digital Forensics
0.0