Wednesday October 8, 2008 5:21 PM AEST
Latest Comments
"Good"
by Francis Ayitey | Oct 6, 2008 10:48 AM
 
"With regard to the battle against cybercrime, Kaspersky Labs, the creator of the famous and ..."
by Mr. Anonymous | Oct 4, 2008 9:08 AM
 
"It does not matter whether the test relies on signature-based testing instead of heuristics, or ..."
by Tony | Oct 3, 2008 8:47 AM
 
"Makes me wonder about other so called off-site mail clients"
by Peter | Oct 3, 2008 12:33 AM
 
"eBay has become unbearable for so many reasons. Some sellers are regrouping at a new internation..."
by Jenny | Oct 2, 2008 9:43 PM

Forensic Toolkit v2.0

  • Email a Friend
  • Print Page
Forensic Toolkit v2.0
Product Info
Supplier:
Product Rating
Features:  5
Ease of Use:  4
Performance:  5
Documentation:  5
Support:  5
Value for Money:  5
Overall Rating:  Overall Rating
 
For: Excellent all-round product
Against: Licence installation can be slightly confusing for first-time users
Verdict: Access Data's Forensic Toolkit 2.0 is a great product that is well put together and worth several times the price. Best Buy
By Justin Peltier
May 19, 2008 3:01 PM
Tags: FORENSIC | TOOLKIT | 2.0
The earlier 1.7 version's primary screen was a grey with many buttons for performing different parts of a forensic investigation. Version 2.0 has a sleeker interface with a tab-based design, but still felt a bit cluttered, thanks to the different windows on each of the tabs that were opened by default.

The FTK Imager utility was able to create a forensic image of the 1GB drive in less than three minutes. The import into the FTK interface took 30 minutes. A new feature allows the investigator to work with the data while it is being imported into the program.

FTK was able to discover the deleted executable, directory and file and could even reconstruct the deleted picture. It detected the password-protected zip file and showed the file contents, but could not open the zip without the password-recovery toolkit.

FTK also found the password-protected Microsoft Word file, but did not spot the steganographed files. The solution includes data-carving features that allow the drive's slack space to be searched for file fragments. The only problems were that the application would crash with large email investigations and only recognised VMWare disk files as flat files and not virtual file systems.

The installation was simple and complex at the same time. The software went in as part of an auto-run utility and the interface for installation was very well laid out. The tricky part was trying to get the licence dongle recognised.

It took several attempts to get the driver installed correctly as the XP OS would recognise the licence fob as a flash drive. Once the driver was set up it was necessary to contact the Access Data server to get the correct licences set up on the fob. This required a call to tech support.

The help file for FTK is the best we have ever seen. It walks you through using the utility with such detail you can learn the tool inside out from the manual.

The pricing for FTK is US$2,995, which is at the low end of the price spectrum, making this an excellent value

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
Complete the SC Reader Survey for your chance to win an iPhone!
 
 
 
Biometrics & Forensics Whitepapers