Blog

Fortifying the Forensics Toolkit (FTK) Portfolio with Exterro Infrastructure

We are not only working to modernize FTK, but to reshape it with the robust features users have been asking for, while injecting powerful new technology to deliver the future of forensics.

The following is the sixth post in a new blog series from Exterro CEO Bobby Balachandran, where he shares his thoughts on the issues legal leaders care about and his vision for addressing them. Read Bobby's last blog here.

One of the primary reasons Exterro sought to acquire AccessData was the capabilities and depth of their flagship point solution, the Forensics Toolkit (FTK®). As we’ve fortified our platform across e-discovery, data privacy, digital forensic investigations, and cybersecurity compliance, we have just begun to scratch the surface of making FTK even more powerful through Exterro AI.

We are not only working to modernize FTK, but to reshape it with the robust features users have been asking for, while injecting powerful new technology to deliver the future of forensics.

The Latest FTK and Enterprise 7.4.2 Updates

The latest release of Enterprise (7.4.2) allows users to collect data from remote endpoints outside the corporate network as well as the cloud. As work environments change, FTK Enterprise has become the first forensic investigation tool that can perform off-network endpoint collection and collect from popular online/cloud data sources like Google Drive and Microsoft Teams.

Additionally, FTK 7.4.2 includes:

  • Enhanced Windows System Information Tab: Presents Windows OS system data (registry files) in an easy-to-read, reportable format.
  • Timeline Analysis: Parses registry files to show an overview of application usage, running processes, physical geolocations, and exact activity times.
  • Network Connectivity Insights: Identifies which networks (home, office, public Wi-Fi) a machine connected to and for how long.

Upcoming Roadmap Highlights

  • Harnessing AI for FTK: We are bringing battle-tested AI to FTK to accelerate access to evidence and surface relevant findings during processing and analysis.
  • A New ‘Smart Investigator’: A virtual investigative partner that leverages AI to reveal contextual insights at the earliest possible stage, shortening case resolution time.
  • FTK Central (Web-Based Review): A high-performance, web-based tool custom-built for forensics and post-breach review. It requires no large infrastructure and can be accessed from any device, including mobile.
  • Processing More Effectively with Macs: Significant investments are being made in Mac enhancements, including support for FileVault 2 decryption.
  • Internet Data & Mobile Parsing: Adding support for all Chromium-based browsers (like Microsoft Edge) and expanding mobile parsing to include GrayKey imports (alongside UFDR and XRY).

It is our mission to be the forensic industry benchmark for operational excellence and a trustworthy partner for corporate legal departments and law enforcement agencies.