: It calculates MD5 and SHA1 hash values to verify data integrity and ensure the evidence has not been altered.

Allows users to browse files and folders before deciding what to image.

Uses MD5 or SHA-1 hashing to ensure the integrity of the captured evidence.

Extract the RAM while the system is still running.

Hash specific files to check for tampering or known malware signatures.

Troubleshooting when running it on modern Windows systems.

Never work on the original evidence.

Never save your image to the same drive you are currently imaging.

FTK Imager Lite is a powerful, portable digital forensics tool used to preview, collect, and image data without making changes to the original evidence. Developed by AccessData (now part of Exterro), this "Lite" version is specifically designed to run from a removable USB device. This allows investigators to perform live acquisitions on a target machine without installing software, which preserves the forensic integrity of the system.

It allows you to mount a forensic image (E01, DD, AFF) as a virtual drive letter in Windows. Because it’s read-only, you can safely analyze the contents with other tools without risking modification.