Step four - create case in Forensic Toolkit (FTK)
Introduction
- This page provides instructions on creating a case in Forensic Toolkit (FTK).
Prepare checklist of digital storage devices
- Log into SharePoint and export register of digital storage devices to Excel.
- Option 1: Export entire register and use Excel filters to filter the list based on Collection ID and/or Accession number.
- Option 2: Use Collection ID and/or Accession number columns to filter the list and create a new list view before exporting the register.
- Option 1: Export entire register and use Excel filters to filter the list based on Collection ID and/or Accession number.
- The exported list is a temporary file. Discard the file after all images have been added to the case in FTK.
Create case in FTK
- Launch FTK.
- Click on Case menu and select New...
- Review the New Case Options window.
- Use the Collection ID or accession number as the Case Name:
- Leave the Reference field blank.
- Provide a brief description of the case that includes the fonds/collection name, types of digital storage devices, and any other information that helps describe the case.
- Optional: Attach a separate description file to the case. For example, you can use this field to attach a deed of gift or processing plan to the case.
- Use the default options for the Case Folder directory (G:\) and Database Directory (leave blank).
- Select evidence processing profile. Most cases should use Field mode.
- Click on each profile to review detailed options.
- Forensic processing: Standard processing options.
- eDiscovery processing: Default processing options of the eDiscovery application.
- Summation processing: Default processing options of the Summation application.
- Basic assessment: Processing options for quickly reviewing the case data.
- Field mode: Field mode disables the standard options when processing evidence. Field mode is the fastest way to add evidence items to a case.
- Customize: Customize the defaults for how evidence added to this case will be pre-processed.
- Forensic processing: Standard processing options.
- When the New Case Options window is complete, click the OK button to build and open the case.
Add evidence items to case
- Add evidence items to case.
- Give
- Add each item to appropriate evidence group (e.g., 3.5 inch floppies, optical discs, computer hard drives).
- Use inventory as a checklist, ensure previous accessioning and registration work is accurate and complete.
- Correct errors or omissions as needed (e.g., edit record in register of digital storage device, create forensic images).
Additional learning resources
Next steps - Run additional analysis processing
See the procedures for running additional analysis processing in FTK.