PTK section:
New Articles
- 2010-07-21 - Robust Process Scanner in PTK Forensics: done!
- 2010-06-01 - Meet the PTK team at The Sleuth Kit and Open Source Digital Forensics Conference
- 2010-05-14 - SANS Investigative Forensic Toolkit e PTK Forensics: made simple!
- 2010-04-26 - DFLabs PTK Forensics new version is available Thru SANS Institute's SIFT Virtual Machine
- 2010-04-24 - New PTK and IncMan suite Video Available for your demo purposes.
- 2010-02-20 - New DFLabs YoutTube Channel.
- 2010-02-04 - PTK Forensics: New Webinar session.
- 2010-02-01 - PTK Forensics, the new website is online.
- 2009-11-14 17:31:11 - New PTK roadmap
- 2009-09-30 14:10:01 - DFLabs is proud to announce that the data carving is available
Validator:
PTK Structure
PTK is an alternative advanced interface for the suite TSK (The SleuthKit). PTK was developed from scratch and besides providing the functions already present in Autopsy Forensic Browser it implements numerous new features essential during forensic activity. PTK is not just a new graphic and highly professional interface based on Ajax technology but offers a great deal of features like analysis, search and management of complex cases of digital investigation.
The core component of the software is made up of an efficient Indexing Engine performing different preliminary analysis operations during importing of every evidence. PTK allows the management of different cases and different levels of multi-users. It is possible to allow more than one investigators to work at the same case at the same time. All the reports generated by an investigator are saved in a reserved section of the Database. PTK is a Web Based application and builds its indexing archive inside a Database MySQL, using thus the construction LAMP (Linux-Apache-MySql-PHP).
PTK main features
- Preliminar indexing phase
- Efficient File analysis
- Dynamic Timeline
- File Categorization
- Gallery view
- Indexed keyword search
- Personal bookmark section
- Cases features shared between multiple investigators
Others features
- Improved Usability, Ajax Based
- Dynamic web application with a centralized database. Now more investigators will be able to better work on the same case simultaneously.
- Memory Dump Analysis
- Exdible with other tools
- Log of all operations
- Many browser are supported.
- PTK is a forensic analysis interface, it is not strictly devoted to incident response
- Its scope is helping small groups of investigators to reach the goal with reduced budget
- Can be furtherly enhanced with the concurrent engineering and development participation
Requirements
PTK needs three requisites for its standard functioning:
- Lynux System
- Apache Server with PHP5
- MySQL server
There are several advantages gained with this configuration. PTK should be implemented on a system having fairly good hardware resources. The suggested requisites are:
- P4 2.33 ghz
- 512 MB of RAM
- 10 GB of Disk (depending on the number of cases managed)
In order to use the abilities of Multi Investigator System (PTK–MIS) and therefore allow different investigators to access a case at the same time it's necessary to have at least 2 GB of RAM. The implementation of PTK is done through a web console dealing with the creation of the pattern in the database and of the administrative user.








