With the release of FTK/FTKC 7.5.2 (March 2022), changes have been made to increase indexing performance. With these changes, a number of file categories have been removed from being indexed by default when using the Forensic Processing & eDiscovery Processing profiles. These excluded categories can be indexed using Additional Analysis. 


The exclusions are listed below.


Category (Parent)

Child

Grandchild

Archives




MS Cabinet



ZIP-Bomb Container


Databases




Other databases




SEE-Encrypted SQLite database

Email




RMS Encrypted Email



Voltage Encrypted Message


Executable (entire category)




Com



Exe



Java Class



Paradox Script



Jar Exe



APK



DEX



ODEX



ELF



Mach-O


Graphics




Raster Graphics (Entire Category)



Embedded Graphics




Snapshot BMP



Word internal BMP



GDSF Embedded BMP



Excel embedded BMP



Interleaf embedded B&W BMP



Interleaf embedded Color BMP



PICT embedded BMP



WPG1 embedded BMP



WPG2 embedded BMP



WKS embedded BMP

Multimedia




Not Verified



Windows Media



RIFF File



Audio (Entire Category)



Video (Entire Category)


OS/File System Files




Disk



Disk Image



Partition


Other Encryption Files




EFS Encrypted Files



Dell Encrypted



PGP (Entire Category)



BestCrypt (Entire Category)

 


TrueCrypt Boot Volume



TrueCrypt Boot Volume Rescue Disk



TrueCrypt Volume


Other Known Types




FileVault



TrueType Font



TrueType Font Collection



TrueType MAC Font



Logical Images (Entire Category)



Physical Images


Slack/Free Space




Unpartitioned Space



File System Slack