Exterro FTK (Forensic Toolkit)
Exterro · 2026
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.
Who it is for, and when
FTK's historical strength is indexing at volume: build the index once and run keyword searches across a very large corpus quickly, which is why it persists in matters where search terms drive the examination rather than artefact recovery. Its distributed processing architecture scales across machines in a way single-workstation tools do not. It also sits close to Exterro's ediscovery products, which suits organisations that want collection and review under one vendor.
What it does not cover
Pricing is quote-based through Exterro sales and the deployment has real infrastructure requirements — a database back end and, for distributed processing, more than one machine — so it is not a laptop tool. Do not confuse it with the free FTK Imager, which shares the brand and does only imaging and preview. Its mobile coverage is not competitive with a dedicated mobile suite, and it does nothing for memory, network, or reverse engineering work.
Go to the source
Open at exterro.com (opens in a new tab)https://www.exterro.com/digital-forensics-software/forensic-toolkit
Details
- Type
- Tool
- Written for
- Working examinerAdvancedWorking examiner, Advanced
- Publisher
- Exterro
- Year
- 2026
- Topics
- commercial-suite, file-systems, ediscovery, reporting, macos, windows
- Checked at source
Related entries
A commercial digital forensics platform that acquires, processes, and reports on computer, mobile, cloud, and vehicle data in a single case, organised around artefact recovery rather than raw file system browsing. AXIOM Cyber is the variant aimed at corporate incident response, internal investigations, and ediscovery, adding remote endpoint collection.
X-Ways Forensics
PaidA commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.
Autopsy
FreeAn open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.
Nuix Workstation
PaidA commercial investigation and data-processing platform aimed at very large unstructured data sets, combining forensic-style processing with ediscovery-grade indexing, deduplication, and export. Nuix now positions its offerings under the Nuix Neo platform, with Workstation still listed as a product alongside Nuix Discover for review.
13Cubed
Partly freeA YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.