Difference between pages "FTK Imager" and "Adroit Photo Forensics"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
(FTK Imager is a data preview and imaging tool that lets you quickly assess electronic evidence to determine if further analysis is warranted.)
 
 
Line 1: Line 1:
FTK Imager is a data preview and imaging tool that lets you quickly assess electronic evidence to determine if further analysis with AccessData® Forensic Toolkit® (FTK™) is warranted. FTK Imager can also create perfect copies (forensic images) of computer data without making changes to the original evidence.
+
{{Infobox_Software |
 +
  name = Adroit Photo Forensics (APF) |
 +
  maintainer = [[Digital Assembly]] |
 +
  os = {{Windows}} |
 +
  genre = {{Analysis}} |
 +
  license = {{Commercial}} |
 +
  website = [http://www.digital-assembly.com/products digital-assembly.com] |
 +
}}
  
With FTK Imager, you can:
+
'''Adroit Photo Forensics''' ('''APF''') is a commercial forensic software package distributed by [[Digital Assembly]].
 +
It specializes in the recovery and analysis of digital photographs.
  
·  Preview files and folders on local hard drives, floppy diskettes, Zip disks, CDs, and DVDs.
+
=Features=
  
·  Create forensic images of local hard drives, floppy diskettes, Zip disks, CDs, and DVDs.
+
Adroit Photo Forensics can parse a number of filesystems, including [[FAT]] 12/16/32, [[NTFS]], [[HFS]], and [[HFS]]. It can
 +
read from [[EnCase]] as well as raw/[[dd]] images.  
  
·  Preview the contents of forensic images stored on the local machine or on a network drive.
+
It is best known for implementing the [[File_Carving:SmartCarving|SmartCarving]] and [[File_Carving:SmartCarving|GuidedCarving]]
 +
algorithms to recover fragmented photos.  
  
·  Export files and folders.
+
== Exif ==
  
·  Generate hash reports for regular files and disk images (including files inside disk images).
+
Adroit Photo Forensics also parses exif data and can be used to view and group files based on exif date stamps instead of
 +
file system date stamps. APF also includes a full zoomable time-line viewer based on exif and file system date stamps.  
  
+
== Other Features ==
  
IMPORTANT: When using FTK Imager to create a forensic image of a suspect's hard drive, make sure you are using a hardware-based write blocking device. This ensures that your operating system does not alter the suspect's hard drive when you attach the drive to your computer.
+
Adroit Photo Forensics interface is optimized for the display of photos. APF also include grouping and sorting options that are
 +
photo relevant.
 +
 
 +
== External Links ==
 +
 
 +
[http://digital-assembly.com/products/adroit-photo-forensics/ Adroit Photo Forensics Product Information]

Revision as of 13:59, 26 October 2009

Adroit Photo Forensics (APF)
Maintainer: Digital Assembly
OS: Windows
Genre: Analysis
License: Commercial
Website: digital-assembly.com

Adroit Photo Forensics (APF) is a commercial forensic software package distributed by Digital Assembly. It specializes in the recovery and analysis of digital photographs.

Features

Adroit Photo Forensics can parse a number of filesystems, including FAT 12/16/32, NTFS, HFS, and HFS. It can read from EnCase as well as raw/dd images.

It is best known for implementing the SmartCarving and GuidedCarving algorithms to recover fragmented photos.

Exif

Adroit Photo Forensics also parses exif data and can be used to view and group files based on exif date stamps instead of file system date stamps. APF also includes a full zoomable time-line viewer based on exif and file system date stamps.

Other Features

Adroit Photo Forensics interface is optimized for the display of photos. APF also include grouping and sorting options that are photo relevant.

External Links

Adroit Photo Forensics Product Information