FTK Imager
Exterro · 2026
Access and status
Cost
Partly free
Part of it is free and part is not. The entry says which part; read that before you plan around it.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.
Who it is for, and when
FTK Imager is the default free imager on Windows and the tool most examiners have actually used to take an image or mount one read-only for a quick look. Its preview mode is genuinely useful on scene: you can confirm a drive contains what the matter is about before committing hours to a full acquisition. Because the format and hash reports are widely recognised, images it produces are unlikely to be questioned on format grounds alone.
What it does not cover
It images and previews; it does not analyse — no keyword indexing, no artefact parsing, no timeline, no case management, all of which sit in the paid FTK product. It is not a write blocker and nothing about running it prevents you from writing to a source device, so hardware or OS-level blocking remains your responsibility. Distribution is via Exterro's site and is gated behind their download form rather than an unconditional public link, and its memory capture is basic compared with a purpose-built acquisition tool.
Go to the source
Open at exterro.com (opens in a new tab)https://www.exterro.com/digital-forensics-software/ftk-imager
Details
- Type
- Tool
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Publisher
- Exterro
- Year
- 2026
- Topics
- imaging, evidence-handling, triage, windows, memory-forensics
- Checked at source
Related entries
A scripted corporate scenario covering the first four weeks of a fictional patent-search company, from 13 November 2009 to 12 December 2009. It ships daily hard drive images and daily RAM captures for each computer, USB drive images, inbound and outbound packet captures, final-day images of every system, and simulated case paperwork including detective reports, warrants and affidavits.
SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.
Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.
KAPE (Kroll Artifact Parser and Extractor)
Partly freeA Kroll-owned Windows triage tool that collects forensically relevant files from a live or mounted system using configurable Targets, then runs parsers over what it collected using Modules. It bypasses file locks with raw disk reads and preserves original timestamps on the copies.