DFFAD - Exterro FTK Boot Camp
Register Now

DFFAD - Exterro FTK Boot Camp


This course provides students with the knowledge and skills necessary to install, configure, and effectively use the combined abilities of AccessData's Forensic Toolkit (FTK), FTK Imager, Registry Viewer, and Password Recovery Toolkit® (PRTK®) to locate and examine email messages, deleted files, free space and file slack. Additionally, students will learn how to search for and export graphic files, export and gain access to encrypted files from multiple industry-standard applications, document digital media information, work with multiple forensic image formats and much more.

Students who attend DFFAD are invited to take the Digital Forensics with FRED (DFF) class at no additional charge.  DFFAD is taught Tuesday-through-Thursday so students can combine DFFAD with the one-day DFF class offered on Mondays.  This makes the best use of each student's travel time and maximizes hands-on instruction with the combined FRED + FTK solution.


This course combines the one-day Digital Forensics with FRED and three-days of FTK Boot Camp.  Additional tools covered and used in class are FTK ImagerTM, Password Recovery Toolkit (PRTKTM), and Registry ViewerTM.

Participants will use Exterro products to conduct forensic investigations on Microsoft® Windows® systems, learning where and how to locate Windows system   artifacts.

Upon course completion, attendees should be able to:

  • Install Exterro software tools
  • Create a case, process and analyze documents, metadata, graphics, and e-mails using FTK
  • Use bookmarks / check marks to efficiently manage and process a case
  • Update / customize the KFF database
  • Manage evidence using file filters
  • Perform searches using regular expressions and imported search lists
  • Carve unallocated disk space
  • Create and customize reports
  • Gain practical experience with FTK indexing
  • Create custom dictionaries using the FTK indexing
  • Create regular expressions
  • Use Registry Viewer to locate evidentiary information in Windows
  • Integrate Registry Viewer with FTK
  • Recover forensic information from Recycle Bin
  • Recovery forensic information from various Windows artifacts


This hands-on class is intended for new users, particularly forensic professionals and law enforcement personnel, who use AccessData forensic software to examine,   analyze and classify digital evidence.

To obtain the maximum benefit from this class, you should meet the following requirements:

  • Read and understand the English language
  • Perform basic operations on a personal computer
  • Have basic knowledge of computer forensic investigations and acquisition procedures
  • Be familiar with the Microsoft Windows environment


Downloadable course syllabus



Date Time Location
Aug 30, 2022 (Tue) -
Sep 01, 2022 (Thu)
Central Time (US & Canada)
Virtual Classroom

Questions? Would you like to learn more?