FTK Bootcamp Intermediate

Level: Intermediate.

Duration: 3 days.

The AccessData BootCamp – Intermediate three-day course provides the knowledge and skills necessary to install, configure, and effectively use Forensic Toolkit (FTK), Password Recovery Tool Kit (PRTK) and Registry Viewer.

Prerequisites

This hands-on class is intended for intermediate users, particularly forensic professionals and law enforcement personnel, who use AccessData forensic software to examine, analyze, and classify digital evidence.

To obtain the maximum benefit from this class, you should meet the following requirements:

Class Materials and Software

You will receive the associated materials prior to the course.

During this three-day, hands-on course, participants will perform the following tasks:

Modules

Module 1: Introduction

Objectives:

Lab:

Participants will install the UTK components—FTK, KFF Library, PRTK, and Registry Viewer

Module 2: FTK Imager 201

Objectives:

Lab:

During the practical participants acquire volatile data from virtual machine, simulating a suspect machine.

Module 3: Registry Viewer 201

Objectives:

Lab:

During the practical, participants use Registry Viewer to search for specific registry keys and recover registry artifacts in a specific order, for a custom report. Students will also create registry summary reports and select summary reports to be run during case processing.

Module 4: Case Setup

Objectives:

Lab:

Students will learn how to copy a case from one version of FTK to another and perform backup and archive functions for cases.

Module 5: Email Analysis

Objectives:

Lab:

Students will walk through a case containing processed email and see the full abilities of FTK to deal with email.

Module 6: Disk Analysis Features

Objectives:

Lab:

Participants will go over the features listed in the topics above, using various evidence files.

Module 7: Advanced Processing Options

Objectives:

Students will use each of the below listed advanced processing options of FTK:

Lab:

During the practical, participants will explore the advanced capabilities of FTK to analyze case data. The steps performed here will walk through the usage of each of the advanced processing options listed above, using various evidence files and cases.

Module 8: Advanced Searching

Objectives:

Students will conduct live and index searches using the follow features of the search tabs:

Lab:

Students will see how to make searches more effective by making subtle to advanced changes to index options and search parameters.

Module 9: Advanced Filtering

Objectives:

Lab:

Participants will build and use complex filters to take large amounts of data and find specific items within that dataset.

Module 10: Visualization

Objectives:

Lab:

Students learn how to use the functionality of the Visualization interface.

Module 11: PRTK 101

Objectives:

Lab:

During the labs, participants will use PRTK to recover passwords from data files. Students will also apply the AccessData Methodology to decrypt files in a sample image. This process will require students to export the FTK case index and Registry Viewer’s registry index to create a custom dictionary, create a biographical dictionary and custom profiles, then re-apply intel gathered from decrypted files to attack other encrypted files.