Legal Cyber Academy
ToolPaidCurrent

Exterro FTK (Forensic Toolkit)

Exterro · 2026

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.

Who it is for, and when

FTK's historical strength is indexing at volume: build the index once and run keyword searches across a very large corpus quickly, which is why it persists in matters where search terms drive the examination rather than artefact recovery. Its distributed processing architecture scales across machines in a way single-workstation tools do not. It also sits close to Exterro's ediscovery products, which suits organisations that want collection and review under one vendor.

What it does not cover

Pricing is quote-based through Exterro sales and the deployment has real infrastructure requirements — a database back end and, for distributed processing, more than one machine — so it is not a laptop tool. Do not confuse it with the free FTK Imager, which shares the brand and does only imaging and preview. Its mobile coverage is not competitive with a dedicated mobile suite, and it does nothing for memory, network, or reverse engineering work.

Go to the source

Open at exterro.com (opens in a new tab)

https://www.exterro.com/digital-forensics-software/forensic-toolkit

Details

Type
Tool
Written for
Working examinerAdvancedWorking examiner, Advanced
Publisher
Exterro
Year
2026
Topics
commercial-suite, file-systems, ediscovery, reporting, macos, windows
Checked at source
  • A commercial digital forensics platform that acquires, processes, and reports on computer, mobile, cloud, and vehicle data in a single case, organised around artefact recovery rather than raw file system browsing. AXIOM Cyber is the variant aimed at corporate incident response, internal investigations, and ediscovery, adding remote endpoint collection.

  • A commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.

  • An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.

  • A commercial investigation and data-processing platform aimed at very large unstructured data sets, combining forensic-style processing with ediscovery-grade indexing, deduplication, and export. Nuix now positions its offerings under the Nuix Neo platform, with Workstation still listed as a product alongside Nuix Discover for review.

  • 13Cubed

    Partly free

    A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.