Exterro FTK Central provides a single platform for collecting, analyzing, and reviewing digital evidence at scale. It supports rapid incident response, detailed forensic examination, and collaborative review while maintaining a documented, defensible investigative process.
Designed for forensic and security investigators, FTK streamlines evidence processing and analysis to shorten investigation time, highlight relevant artifacts, and help investigators reach documented, defensible conclusions.
The Exterro FTK portfolio scales from individual examiners to enterprise-wide investigations, providing consistent workflows and defensible outcomes without forcing teams to retool as complexity grows.
A workstation-based forensic application designed for individual examiners and air-gapped environments. Combines acquisition and analysis in a single install with no database dependency.
A centralized, multi-user forensic platform for shared evidence, distributed processing, permissions, and workflow orchestration, ideal for DFIR teams, internal investigations, and large case volumes
Professional-grade field and rapid-response acquisition with secure preview, credential-based decryption, targeted collection, and full-disk imaging to quickly identify and preserve critical evidence.
Large-scale remote preview and acquisition across enterprise environments.
Automation and orchestration engine that integrates FTK Central with SIEM, SOAR, ticketing, and case management systems to support incident-driven evidence collection.
Native connectors for modern collaboration and cloud sources (e.g., Microsoft 365, Google Workspace), preserving artifacts and metadata for forensic review.
Accelerated forensic triage and review using privacy-first, auditable AI
Enterprise-scale discovery and collection of mobile data, enabling organizations to identify, collect, and review evidence across large custodian populations without seizing devices.
Exterro Smart Breach Review™ applies Exterro Intelligence to rapidly identify exposed sensitive data and support breach.
Together, these capabilities shift digital forensics from reactive case handling to proactive, intelligence-driven investigation, helping teams respond faster, reduce downstream risk, and strengthen defensibility.



Together, these capabilities shift digital forensics from reactive case handling to proactive, intelligence-driven investigation, helping teams respond faster, reduce downstream risk, and strengthen defensibility.

Exterro brings digital forensics together in a single FTK-driven investigation workflow. But the real advantage shows up when those forensic capabilities are connected to the broader Exterro Platform, so investigations move faster, scale better, and actually hold up under scrutiny.