Recently I've been doing a lot of imaging and mounting different image format types. Xmount(1) has been very handy and not something I've used a lot in the past. Xmount can do DD, EWF (Expert Witness Compression Format), or AFF. While mount disks haven't changed a lot, having a combined utility that can do the significant files types makes it more accessible.
#apt-get install xmount Now you should have a VMDK file in /tmp/ewf. You can now add this file as a disk to an existing Vmware Machine or create a new virtual machine and boot off it. Any other new forensics tools you have run across recently that makes life easier for forensicators? Leave a comment. 1 https://www.pinguin.lu/xmount -- Tom Webb @twsecblog |
Tom 59 Posts ISC Handler Nov 5th 2021 |
Thread locked Subscribe |
Nov 5th 2021 6 months ago |
Sign Up for Free or Log In to start participating in the conversation!