SlideShare a Scribd company logo
6
Most read
8
Most read
12
Most read
How to boot a VM from
a Forensic Image
Krešimir Hausknecht, M.Sci.
PLEASE BE CAREFULL!
This process will probably change your
original evidence so please make sure
that it is being done on a copy!!
2
VirtualBox & FTK Imager
Install:
1. FTK Imager
2. VirtualBox
• https://www.virtualbox.org/wiki/Downloads - VirtualBox 5.0.20 for
Windows hosts x86/amd64
3
1. FTK Imager
1. File → Image Mounting
2. Select E01 image you want to mount
4
1. FTK Imager
3. Mount type: physical only
4. Mount method: block device/writeable
5. Write cache folder: C:tempVBox_cache
• Choose a preferred destination cache folder
6. Mount – you will see which physical drive the image is
mapped to
• Note the Physical drive number, we’ll need that later…
5
6
2. Create a new folder
For storing the virtual disk file later
Eg. C:tempVbox_temp
7
3. Command prompt
Run as administrator!!
cd c:Program FilesOracleVirtualBox
vboxmanage internalcommands createrawvmdk -filename
C:tempVbox_tempimage.vmdk -rawdisk .physicaldriveX
Replace the path, file name and physical drive accordingly
8
4. VirtualBox
Run as administrator!
Creating a new virtual machine:
• Name: image
• Type: Microsoft Windows
• Version: <Select accordingly>
• Memory size: 2GB RAM
• Hard disk: use an existing virtual hard disk file → image.vmdk
• File we created in the step before
• START the machine
• Cross you fingers!
9
10
Issues
When dismounted and mounted again – doesn’t work!
• Windows Error Recovery (Launch startup repair or start windows
normally)
• Delete the following folder:
• C:Usersuser.VirtualBox
• Repeat the procedure
It will not always work 
11
Questions
Kresimir.hausknecht@insig2.eu
https://hr.linkedin.com/in/kresimirhausknecht

More Related Content

PDF
Booting an image as a forensically sound vm in virtual box
PDF
File System Implementation - Part1
PDF
Big Data: SQL on Hadoop from IBM
DOCX
How to configure flexible netflow export on cisco routers
PPT
Case study windows
PPTX
Window architecture
PPT
Linux Kernel Image
PPTX
Tabla comparativa de los sistemas operativos
Booting an image as a forensically sound vm in virtual box
File System Implementation - Part1
Big Data: SQL on Hadoop from IBM
How to configure flexible netflow export on cisco routers
Case study windows
Window architecture
Linux Kernel Image
Tabla comparativa de los sistemas operativos

What's hot (20)

PDF
Linux Porting to a Custom Board
PPTX
file system in operating system
PDF
LAS16-111: Easing Access to ARM TrustZone – OP-TEE and Raspberry Pi 3
PDF
Embedded Systems: Lecture 7: Lab 1: Preparing the Raspberry Pi
PPT
Windows Server 2008 R2 Overview
PDF
Bootloaders
PDF
File system is full - what do i do
PPT
Byte code jvm
PDF
Implementing role based access control on Web Application (sample case)
PDF
5 p9 pnor and open bmc overview - final
PPTX
File system.
PDF
Entendiendo el .NET Framework
PDF
LCU14 302- How to port OP-TEE to another platform
ODP
File system hiearchy
PDF
Mapa Mental Comandos Unix E Linux
PPTX
Introduction to HDFS
PDF
Unix commands
PDF
HKG15-311: OP-TEE for Beginners and Porting Review
PDF
File System Hierarchy
PDF
SFO15-200: Linux kernel generic TEE driver
Linux Porting to a Custom Board
file system in operating system
LAS16-111: Easing Access to ARM TrustZone – OP-TEE and Raspberry Pi 3
Embedded Systems: Lecture 7: Lab 1: Preparing the Raspberry Pi
Windows Server 2008 R2 Overview
Bootloaders
File system is full - what do i do
Byte code jvm
Implementing role based access control on Web Application (sample case)
5 p9 pnor and open bmc overview - final
File system.
Entendiendo el .NET Framework
LCU14 302- How to port OP-TEE to another platform
File system hiearchy
Mapa Mental Comandos Unix E Linux
Introduction to HDFS
Unix commands
HKG15-311: OP-TEE for Beginners and Porting Review
File System Hierarchy
SFO15-200: Linux kernel generic TEE driver
Ad

Viewers also liked (10)

PDF
File000150
PPTX
мобільні операційні системи [автосохраненный]
PPTX
мобільні операційні системи [автосохраненный]
PPT
Mac Forensics
PPTX
Windows 8 Forensics & Anti Forensics
PPT
Linux forensics
PDF
Windows 8.x Forensics 1.0
PPT
WhatsApp Forensic
PPTX
Windows 10 Forensics: OS Evidentiary Artefacts
PPTX
Types of Irrigation
File000150
мобільні операційні системи [автосохраненный]
мобільні операційні системи [автосохраненный]
Mac Forensics
Windows 8 Forensics & Anti Forensics
Linux forensics
Windows 8.x Forensics 1.0
WhatsApp Forensic
Windows 10 Forensics: OS Evidentiary Artefacts
Types of Irrigation
Ad

Recently uploaded (20)

PPTX
Big Data Technologies - Introduction.pptx
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
KodekX | Application Modernization Development
PPTX
Spectroscopy.pptx food analysis technology
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Empathic Computing: Creating Shared Understanding
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
MYSQL Presentation for SQL database connectivity
PPT
Teaching material agriculture food technology
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Big Data Technologies - Introduction.pptx
Machine learning based COVID-19 study performance prediction
Understanding_Digital_Forensics_Presentation.pptx
KodekX | Application Modernization Development
Spectroscopy.pptx food analysis technology
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Unlocking AI with Model Context Protocol (MCP)
Empathic Computing: Creating Shared Understanding
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Chapter 3 Spatial Domain Image Processing.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Reach Out and Touch Someone: Haptics and Empathic Computing
Building Integrated photovoltaic BIPV_UPV.pdf
The AUB Centre for AI in Media Proposal.docx
MYSQL Presentation for SQL database connectivity
Teaching material agriculture food technology
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...

How to boot a VM form a Forensic Image

  • 1. How to boot a VM from a Forensic Image Krešimir Hausknecht, M.Sci.
  • 2. PLEASE BE CAREFULL! This process will probably change your original evidence so please make sure that it is being done on a copy!! 2
  • 3. VirtualBox & FTK Imager Install: 1. FTK Imager 2. VirtualBox • https://www.virtualbox.org/wiki/Downloads - VirtualBox 5.0.20 for Windows hosts x86/amd64 3
  • 4. 1. FTK Imager 1. File → Image Mounting 2. Select E01 image you want to mount 4
  • 5. 1. FTK Imager 3. Mount type: physical only 4. Mount method: block device/writeable 5. Write cache folder: C:tempVBox_cache • Choose a preferred destination cache folder 6. Mount – you will see which physical drive the image is mapped to • Note the Physical drive number, we’ll need that later… 5
  • 6. 6
  • 7. 2. Create a new folder For storing the virtual disk file later Eg. C:tempVbox_temp 7
  • 8. 3. Command prompt Run as administrator!! cd c:Program FilesOracleVirtualBox vboxmanage internalcommands createrawvmdk -filename C:tempVbox_tempimage.vmdk -rawdisk .physicaldriveX Replace the path, file name and physical drive accordingly 8
  • 9. 4. VirtualBox Run as administrator! Creating a new virtual machine: • Name: image • Type: Microsoft Windows • Version: <Select accordingly> • Memory size: 2GB RAM • Hard disk: use an existing virtual hard disk file → image.vmdk • File we created in the step before • START the machine • Cross you fingers! 9
  • 10. 10
  • 11. Issues When dismounted and mounted again – doesn’t work! • Windows Error Recovery (Launch startup repair or start windows normally) • Delete the following folder: • C:Usersuser.VirtualBox • Repeat the procedure It will not always work  11