Icon Menu
Icon Search

Forensic Toolkit (FTK)

FTK was recognised around the world as the standard in computer forensic software, FTK is the state-of-the-art, court- cited digital investigations solution built for speed, scalability and ease of use. It provides increased comprehensive processing, collection and data analysing 50% faster than before, which means smaller backlogs and better response time, resulting in reduced costs. It’s the only solution that utilises a single case database, creating a clear picture of the event. Due to its architecture, FTK can be setup for distributed processing and incorporate web-based case management and collaborative analysis.

Zero in on relevant evidence quickly, conduct faster searches and dramatically increase analysis speed with FTK®, the purpose-built solution that interoperates with mobile device and e-discovery technology. Powerful and proven, FTK processes and indexes data upfront, eliminating wasted time waiting for searches to execute. No matter how many different data sources you’re dealing with or the amount of data you have to cull through, FTK gets you there quickly.


FTK uses distributed processing and is the only forensics solution to fully leverage multi-thread/multi-core computers. While other forensics tools waste the potential of modern hardware solutions, FTK uses 100 percent of its hardware resources, helping investigators find relevant evidence faster.


Since indexing is done up front, filtering and searching are completed more efficiently than with any other solution. Whether you’re investigating or performing document review, you have a shared index file, eliminating the need to recreate or duplicate files.


FTK is truly database driven, using one shared case database. All data is stored securely and centrally, allowing your teams to use the same data. This reduces the cost and complexity of creating multiple data sets.

FTK Featured Video

Built to interoperate with mobile and e-discovery solutions, FTK helps you find relevant evidence faster, dramatically increase analysis speed and reduce backlog. It's the only solution that utilizes a single case database, creating a clear picture of the event.

Key Product Features

FTK provides real-world features that help teams make sense of and manage massive data sets, separate critical data from trivial details, and protect digital information while complying with regulations.

  • Unmatched speed through distributed processing engines

  • Unique architecture provides better stability

  • Wizard-driven to ensure no data is missed

  • State-of-the-art data visualization to highlight relationships and patterns

  • Only solution that utilizes a single case database, reducing cost and complexity of multiple case datasets

  • Faster learning with easy-to-use GUI

Capabilities To Empower You

  • Export your data into a portable case for offline review. No need to spend time generating reports that can only be viewed in a couple of different formats. Portable case makes your life easier with a quick export. Reviewers will appreciate the ability to view the data in a near native format.

  • Get a head start on your investigation with URL detection and parsing capabilities across devices without regard to browser, neatly organized under one section to easily review the data and connect the dots in your investigation.

  • FTK will ingest and support updated versions of LX01 and E01 images.

  • Automatically import and expand a nested forensic image with image within an image support.

  • Import and parse AFF4 images created from Mac® computers (generated by third-party solutions like MacQuisition by BlackBag).

  • Parse XFS file systems when investigating and collecting from RHEL Linux environments.

  • Leverage the power of your forensic environment with optimized support for unified database for the AWS/Amazon RDS configuration. Host your FTK database in AWS to upload, process and review for unmatched speed and scalability.

  • Cut down on OCR time by up to 30% with our efficient OCR engine.

  • Locate, manage, and filter mobile data more easily with a dedicated mobile tab. Use the message application filter to quickly isolate data from message applications like WhatsApp or Facebook.

  • View all associated EXIF data, including location, make and model of the device used to capture the images or video.

  • Collect, process and analyze datasets containing Apple file systems that are encrypted, compressed or deleted.

  • Decrypt a computer drive encrypted by the latest version of McAfee Drive Encryption and new L01 export support which eases the workflow of users when data must be used within multiple tools.

  • Custom processing options help establish enterprise-wide processing standards, creating consistency for your investigations and reducing the possibility of missed data.

  • The easy-to-use GUI provides a faster learning experience.

  • Visualization technology that displays your data in timelines, cluster graphs, pie charts, geolocation and more, helps you get a clearer picture of events.