I just had a sort of general question as to whether or not it is possible to use a captured raw dd image in FTK. I would like to use the image to perform a forensic analysis on the contents of the drive and need to use raw dd since it is a sector by sector copy.
I have a one terabyte image captured but the resulting image is only ~92 GB, I’m assuming due to compression? But I also thought you couldn’t compress a raw dd image. The image extension is also .000 when typically raw images start at .001.
When I try to load the image into FTK it only displays “GZIP” in the evidence tree but has no content. I’ve tried capturing the image many different times with the same results. Not sure if anyone will know, just thought I would ask