Capturing Memory and Obtaining Protected Files with FTK Imager – eDiscovery Best Practices
Capturing Memory and Obtaining Protected Files with FTK Imager – eDiscovery Best Practices https://cloudnine.com/wp-content/themes/cloudnine/images/empty/thumbnail.jpg 150 150 CloudNine https://cloudnine.com/wp-content/themes/cloudnine/images/empty/thumbnail.jpg
Over the past few weeks, we have talked about the benefits and capabilities of Forensic Toolkit (FTK) Imager from AccessData (and obtaining your own free copy), how to create a disk image, how to add evidence items for the purpose of reviewing the contents of those evidence items (such as physical drives or images that you’ve created) and how to export files and create a custom content image of a targeted collection of files with FTK Imager. This week, let’s discuss how to Capture Memory and Obtain Protected Files to collect a user’s account information and possible passwords to other files.
read more




