Data visualization with FTK
This tool allows you to create and filter timelines, split data into categories, view emails and related metadata, analyze traffic and social connections, and observe geolocation data in a user-friendly environment. It also allows the user to specify a particular theme or color scheme, giving it a customizable feel.
Getting ready
Open FTK and load up a case (if you are not sure how to do this, see the section Drive acquisition in E01 format with FTK Imager in Chapter 3, Windows Drive acquisition.)
Choose a dataset within the case, then click the visualization icon in the top right-hand side of the screen. This will launch the visualization tool.
How to do it...
There are various possible uses for the visualization tool, so we will go through them one at a time:
- Firstly, you can change the theme of FTK should you wish to do so. You can do this by going to
CaseManager|
Tools|
Preferences
in FTK, which will then open up a box which lists several options. These correspond...