Hi everyone,
A few questions for anyone using FTK in their digital forensics workflows. FTK provides a few "processing profiles" that can be used when disk images are added to a case. You can also create custom processing profiles and perform "additional analysis" on images after they have been added.
Has anyone created a custom profile to suite your archival workflows? Or are you using an FTK default profile? Do you have a core set of additional analysis options you run after the images are added? Or is it case by case?
There seems to be two choices when building a case: do all the processing at once OR do some minimal processing when images are added and then do some additional analysis.
Some of the options are very time consuming (e.g., flagging duplicates, checking files against the NSRL, expanding compound files, etc.) and may not be necessary all of the time.
I'd love to hear from FTK users in the cultural heritage communities about how they approach these decisions when building a new case in FTK.
Cheers,
Creighton Barrett
Digital Archivist
Dalhousie University Archives