Book Image

Computer Forensics with FTK

By : Fernando Carbone
Book Image

Computer Forensics with FTK

By: Fernando Carbone

Overview of this book

<p>With the increase of electronic crimes and the need to constantly audit the proper use of resources, companies need qualified professionals and appropriate tools to carry out these activities. The FTK platform, with the ability to collect and analyze digital evidence quickly and with integrity, is a great solution to help professionals achieve these goals. It is extremely useful for conducting digital investigations, helping you conduct a thorough investigation through a single tool and ensure the integrity of evidence. It is hard to find technical information on this tool and that’s where this book will come in handy, helping professionals perform their activities with greater excellence.</p> <p>This tutorial leads by example, providing you with everything you need to use FTK and the tools included such as FTK Imager, Registry View, and PRTK in order to enhance your Computer Forensics knowledge in an easier and more efficient way.</p> <p>You will be introduced to the background of Computer Forensics, which include the types of digital devices that can be acquired and how to prepare for a new case of investigation. You will become acquainted with the FTK architecture and learn how to leverage its features in order to help you find the evidence as fast as possible. Through this book, you will also learn the memory forensics technique using the memory dump feature of FTK Imager. Furthermore, you will learn how to extract some important information such as process and DLL information, Sockets, and Driver List Open Handles.</p> <p>To conclude your tutorial, you will learn how to extract information from Windows Registry and how to recover passwords from the system and files. You will find this book an invaluable supplement to teach you all the steps required for the completion of investigations on digital media and to generate consistent and irrefutable evidence in court.</p>
Table of Contents (14 chapters)
Computer Forensics with FTK
Credits
About the Author
About the Reviewers
www.packtpub.com
Preface
Free Chapter
1
Getting Started with Computer Forensics Using FTK
Index

About the Reviewers

Gretchen Gueguen is an archives and library consultant, specializing in digital libraries and technology. She has held the position of Digital Archivist at the University of Virginia where she created the first born-digital archives management and digital forensics programs. She has previously worked on digital library projects at East Carolina University and the University of Maryland. She began her journey in digital humanities at the Maryland Institute for Technology in Humanities, working on the Thomas MacGreevy Archive.

Jacob Heilik has worked for 35 years in law enforcement (regulatory compliance and criminal investigation) with the Canadian Federal Government. The last 10 years of his career were spent learning and practicing digital forensics—searching and seizing in the field, analyzing in the lab, and managing a talented team of examiners and analysts. Since retiring from public service in 2009, he has concentrated his efforts on improving digital forensic skills in law enforcement.

Striving to be a positive influence, aiming to improve everything he is involved with, he has helped to train officers from around the world, being involved with projects sponsored by Interpol, Europol, the European Cybercrime Training and Education Group, and University College Dublin.

Faraz Siddiqui has obtained a BS in Forensic Chemistry. Somewhere along his career, he decided to go back to school to pursue something more technical. He obtained an MS in Digital Forensics and has been working in the Computer Security field ever since. When he is not occupied with his obsessions about the latest technology, he loves to spend his time with his beautiful wife and children.