Exterro FTK Imager is a forensic imaging and preview tool for acquiring and preserving digital evidence. It creates full disk images in industry-standard formats and checks them using MD5 or SHA-1 hashes. Investigators can preview files and folders before full acquisition to identify relevant material. The tool can also capture volatile RAM and registry data from a live device, read and write common forensic image formats, and export files for analysis in FTK Forensic Toolkit. Supported sources include Windows and Linux hard drives, CDs and DVDs, thumb drives, and other USB devices. FTK Imager runs on Windows only, although it can image Linux devices, and it does not collect directly from phones or other mobile devices. Exterro lists the base FTK Imager plan at 0.00 USD per free. FTK Imager Pro costs 499.00 USD per year and adds encryption-aware workflows, iOS advanced logical collection, faster preview, and targeted acquisition. Exterro identifies incident response and DFIR teams, law enforcement, forensic examiners, and corporate security and HR investigators as users.
Who it is for
FTK Imager suits incident response and DFIR teams, law enforcement and forensic examiners, and corporate security or HR investigators who need to image and preview digital evidence.
What is good
- Creates disk images and validates them with MD5 or SHA-1.
- Previews files and folders before full acquisition.
- Captures volatile RAM and registry data from live devices.
- Base FTK Imager plan is listed at 0.00 USD per free.
What to know first
- Runs on Windows only, though it can image Linux devices.
- Does not collect directly from phones or mobile devices.
- Pricing for the product is listed as on request.
Verdict
FTK Imager provides imaging, preview, validation, and live memory capture for digital investigations. Its Windows-only installation and lack of direct mobile collection are important limits to consider.
Exterro FTK Imager plans and pricing
All plansCompared on digital forensics software
- Free plan
- Yes
- Evidence sources
- Live enterprise endpoints; Windows, macOS, and selected Linux artifacts; Microsoft 365; Exchange; SharePoint; OneDrive; Google Workspace; Gmail; Google Drive; Slack; Microsoft Teams; Confluence; AFF4; E01; AD1; RAW/DD
- Mobile forensics
- No
- Disk imaging
- Yes
- Memory forensics
- Yes
- Case collaboration
- Yes
- Supported platforms
- Windows, macOS, Linux
- Export formats
- E01, AFF, RAW


