Chapter 5 AccessData’s Forensic Toolkit

DOI: 10.1201/9781003134817-5

Creating a case

Let us work through a case with AccessData’s Forensic Toolkit (ADFTK). Just so you can see what it looks like if no case data has been loaded yet (i.e., starting a brand new case with no loaded sources), let us go through the process (see Figure 5.1). Of course the version of the tool you are using may be different and as such could look different.

Figure 5.1 Evidence information.

Click OK, which opens the Wizard for Creating a New Case. Enter the Case Information and the Case Description, then click Next.

On the Case Log Option screen, you can select any ...

Get Cyber Crime Investigator's Field Guide, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.