Forensics investigation involves the acquisition, preservation, analysis, and presentation of computer evidence. This type of evidence is fragile in nature and can easily, even inadvertently be altered, destroyed, or rendered inadmissible as evidence. Computer evidence must be properly obtained, preserved, and analyzed to be accepted as reliable and valid in a court of law.


The objective of this lab is to provide expert knowledge about the AccessData FTK used in computer forensics.
Forensics Investigation Using AccessData FTK


James Smith is an employee of a reputed forensic investigation firm. He has been hired by a private organization to investigate a cybercrime scene. As an expert computer forensic investigator, he has to acquire, preserve, analyze, and present valid evidence in a court of law.

Incident Handling Exercises / Forensics Investigation Using AccessData FTK contains the following Exercises:

  • Investigating a Case Using AccessData FTK

