Drive and memory acquisition using FTK Imager in Wine
There are several tools for Windows systems that you may wish to take advantage of to be able to capture the memory and paging files on a Windows device. The forensic images can then be opened on your Kali machine for analysis, using Volatility 3 for memory analysis and Autopsy for drive analysis. Let’s first look at installing and using FTK Imager within Wine in Kali Linux.
Installing FTK Imager
FTK (Forensic Toolkit) Imager is a free Windows tool for the live acquisition of memory (RAM), the paging file, and drive images.
Follow these steps to install FTK Imager in Kali Linux to create forensic acquisitions:
- First, download FTK Imager from the official website at https://go.exterro.com/l/43312/2022-08-23/f7rytx. Enter all relevant detail on the registration page. Once all fields are completed, click on the Submit button, and you will be prompted to download the application.
- Once downloaded, click on...