How can I run FTK I...
 
Notifications
Clear all

How can I run FTK Imager on Mac systems?

12 Posts
6 Users
0 Likes
23.8 K Views
(@demir)
Posts: 13
Eminent Member
Topic starter
 

if anybody help me,

I will be happy.

I want to install ftk on mac pc and I want to run FTK on mac pc so I want to get image of it's hard drive..

We do not face with Mac systems, Mostly we face with Windows based computers.

 
Posted : 02/03/2018 12:35 pm
AmNe5iA
(@amne5ia)
Posts: 173
Estimable Member
 

Why run FTK Imager on a Mac? But if you must AccessData have you covered, kind of.

 
Posted : 02/03/2018 12:41 pm
(@demir)
Posts: 13
Eminent Member
Topic starter
 

For example

FTK Imager 3.1.1 command line

for MAC OS 10.5 AND 10.6X VERSION

on accessdata this is available.

command line versions.

I do not know how to run this.

I am new to Mac systems

 
Posted : 02/03/2018 12:50 pm
AmNe5iA
(@amne5ia)
Posts: 173
Estimable Member
 

They even wrote a handy guide for people who haven't used it before.

 
Posted : 02/03/2018 1:23 pm
(@demir)
Posts: 13
Eminent Member
Topic starter
 

Oh Sorry,

You are right.

I did not see it.

Thanks for making me to realize it.

I read it.

I will try.

 
Posted : 02/03/2018 2:04 pm
(@armresl)
Posts: 1011
Noble Member
 

Is your avatar supposed to be Darth Potato?

Blacklight has mac osx forensics products, and there is also Sumuri. Nuix workstation is great and works on macs, although it is expensive.

For imaging disks on mac osx you can use the terminal. Installing homebrew makes your life easier. You can use your favourite imagers like dcfldd, dc3dd etc. after installing brew.

https://www.blackbagtech.com/software-products.html
https://sumuri.com
https://www.nuix.com
https://brew.sh

 
Posted : 02/03/2018 11:01 pm
(@randomaccess)
Posts: 385
Reputable Member
 

Blacklight has mac osx forensics products, and there is also Sumuri. Nuix workstation is great and works on macs, although it is expensive.

Two main imaging tools worth mentioning
Blackbag Technologies make Macquisition (Blacklight is their examination tool, also good, and can deal with APFS encryption in the application which is handy).
Sumuri make Paladin, which is free, and allow you to boot in and create a dd/e01 image, but won't help if you image is encrypted.
Sumuri also make Recon Imager, which has an MacOS bootable partition with imager and will let you mount the hfs+ volume and decrypt it if you need to.

That being said, I recommend people image both disk0 and the decrypted volume because you can then restore the original drive to an external and boot that on another mac to see how people act.

Otherwise, for live systems, yes FTK Imager has a mac version, but there's always the inbuilt dd command, or you can install ewftools or dc3dd etc.

For the free option, I would get a Paladin disk loaded up
If youve got the cash, recon imager and macquisition are worth it (they're relatively cheap too)

 
Posted : 03/03/2018 4:45 am
jaclaz
(@jaclaz)
Posts: 5133
Illustrious Member
 

Is your avatar supposed to be Darth Potato?

This is Darth Potato.

Hmmm.

Darth-cat is NOT amused (

jaclaz

 
Posted : 03/03/2018 4:57 pm
(@c-wawrentowicz)
Posts: 26
Eminent Member
 

I tried like you in the end I bought BlackBag MACQUISITION. It resolved my all problems

 
Posted : 04/03/2018 11:12 am
(@demir)
Posts: 13
Eminent Member
Topic starter
 

Thanks for the Reply.

 
Posted : 06/03/2018 1:32 pm
Page 1 / 2
Share: