While most tools stop at simple alerts or leave you with isolated data, Exterro FTK takes you directly from the initial investigative trigger to a fully defensible outcome. Unify your approach to enterprise data collection, incident response, internal investigations, and deep forensic analysis on a single platform designed to uncover hard evidence and drive better, faster decisions.
Designed for forensic and security investigators, FTK streamlines evidence processing and analysis to shorten investigation time, highlight relevant artifacts, and help investigators reach documented, defensible conclusions.
The Exterro FTK portfolio scales from individual examiners to enterprise-wide investigations, providing consistent workflows and defensible outcomes without forcing teams to retool as complexity grows.
A workstation-based forensic application designed for individual examiners and air-gapped environments. Combines acquisition and analysis in a single install with no database dependency.
A centralized, multi-user forensic platform for shared evidence, distributed processing, permissions, and workflow orchestration, ideal for DFIR teams, internal investigations, and large case volumes
Professional-grade field and rapid-response acquisition with secure preview, credential-based decryption, targeted collection, and full-disk imaging to quickly identify and preserve critical evidence.
Large-scale remote preview and acquisition across enterprise environments.
Automation and orchestration engine that integrates FTK Central with SIEM, SOAR, ticketing, and case management systems to support incident-driven evidence collection.
Native connectors for modern collaboration and cloud sources (e.g., Microsoft 365, Google Workspace), preserving artifacts and metadata for forensic review.
Accelerated forensic triage and review using privacy-first, auditable AI
Enterprise-scale discovery and collection of mobile data, enabling organizations to identify, collect, and review evidence across large custodian populations without seizing devices.
Exterro Smart Breach Review™ applies Exterro Intelligence to rapidly identify exposed sensitive data and support breach.
Together, these capabilities shift digital forensics from reactive case handling to proactive, intelligence-driven investigation, helping teams respond faster, reduce downstream risk, and strengthen defensibility.

Together, these capabilities shift digital forensics from reactive case handling to proactive, intelligence-driven investigation, helping teams respond faster, reduce downstream risk, and strengthen defensibility.



Exterro brings digital forensics together in a single FTK-driven investigation workflow. But the real advantage shows up when those forensic capabilities are connected to the broader Exterro Platform, so investigations move faster, scale better, and actually hold up under scrutiny.
Everything you need to know about our digital forensics products in one place.
Exterro FTK (Forensic Toolkit) by Exterro is a digital forensics software platform used to collect, process, analyze, and review digital evidence from computers, mobile devices, cloud services, and network endpoints. It is used by law enforcement for criminal investigations, corporate security for internal investigations and incident response, government agencies, and legal professionals for litigation support. FTK is a widely recognized industry standard whose evidence methodology is accepted in courts globally.
Yes, FTK Imager is a free forensic imaging and preview tool provided by Exterro. It creates forensic images in E01, AFF, and DD formats with hash verification to ensure evidence integrity. Available for free download at exterro.com/ftk-downloads. It is a separate free tool from the commercial FTK suite and requires no license.
Exterro FTK standalone is a single-examiner workstation for individual investigators handling cases locally. Exterro FTK Central is an enterprise distributed forensics platform enabling multiple examiners to work simultaneously on shared evidence in a centralized repository — designed for forensics labs, agencies, and corporations handling both high volumes of investigations and complex, extremely large data sets.
FTK Enterprise enables agentless remote forensic collection from endpoints across a network without physical device access. Investigators initiate collections from a central console — specifying full images, specific file types, memory dumps, or targeted artifacts — and collections are transmitted securely. Essential for corporate investigations involving distributed employees and rapid incident response across hundreds of endpoints simultaneously. Exterro Remote Mobile Discovery extends these capabilities to include wireless collection from remote mobile devices.
Exterro Smart Breach Review is an AI-powered tool that automates identification and classification of personal data within large volumes of breach-related documents. After a security incident, organizations must determine what personal data was exposed to fulfill breach notification obligations under GDPR and CCPA. Smart Breach Review uses machine learning to rapidly scan breach files and identify sensitive data types — dramatically reducing time and cost compared to manual review.
Exterro FTK is known for comprehensive full-disk forensics, enterprise scalability through FTK Central, broad cloud data source collection, and SIEM/SOAR integration via FTK Connect with 200+ connectors. Magnet Axiom specializes in artifact-based recovery across computers, mobile, and cloud. Cellebrite UFED is dominant for mobile device extraction in law enforcement. FTK uniquely integrates with Exterro's eDiscovery and data governance platforms, offers the free Exterro FTK Imager tool, and provides AI-powered breach review — making it the strongest choice for organizations needing unified forensics, eDiscovery, and legal discovery.
Yes. Exterro FTK supports collection from Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive), Google Workspace, Slack, Box, Dropbox, and 200+ cloud and SaaS services. Cloud collection is now essential in digital forensics because a significant proportion of relevant evidence in corporate investigations and cybercrime cases resides in cloud platforms rather than on physical devices.