Converting VM to dd...
 
Notifications
Clear all

Converting VM to dd file

17 Posts
7 Users
0 Reactions
5,820 Views
(@dbarrett)
Active Member
Joined: 18 years ago
Posts: 14
Topic starter  

Hi All,
I am trying to put together some procedures for examining virtual machines found on an acquired hard drive. I am curious as to experiences in this realm. I want to include all types of VMs and am looking for tools that can convert a VM file to a dd file. Any help would be appreciated.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

FTK Imager will open .vmdk files and let you "acquire" them to dd
http//windowsir.blogspot.com/2008/02/getting-started-or-forensic-analysis-on.html


   
ReplyQuote
pronie2121
(@pronie2121)
Estimable Member
Joined: 17 years ago
Posts: 117
 

I agree the .vmdk file is where all of that good information is. I did experience some trouble in using FTK to analyze the virtual machine. EnCase was much more beneficial in this aspect. If you would like I have produced a report on virtual machine analysis.


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

I for one would love to see your report on VM analysis.


   
ReplyQuote
pronie2121
(@pronie2121)
Estimable Member
Joined: 17 years ago
Posts: 117
 

I will get that over to you as soon as possibly


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
 

FTK imager is by far and away the easiest way to "acquire" a .vmdk to a dd image. FTK itself can parse .vmdk but I prefer to convert to dd for simplification. This is the method I use when I create class materials for trainings.

qemu-img can convert to dd as well.


   
ReplyQuote
(@dbarrett)
Active Member
Joined: 18 years ago
Posts: 14
Topic starter  

pronie2121,
I would like to see your report as well. I will also be working on other VMs such as those created by Virtual PC, and Parallels.
Hogfly,
Thanks for the tip on qemu-img. We have been using VirtualBox quite a bit, so I will look at this as well.
keydet89,
Thanks for the link to some great information. I will have to revisit FTK Imager. (I thought we looked at it.)


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
 

dbarrett,
If you haven't seen it yet I had a blog entry on virtualbox. The comments include a tip on working with dynamic images as well.

http//forensicir.blogspot.com/2008/01/virtualbox-and-forensics-tools.html


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Also you can mount the .vmdk file with VDK and use dsfo/dsfi or dd for windows to dd the \\.\Physicaldriven to a RAW image.

jaclaz


   
ReplyQuote
(@jimmyw)
Trusted Member
Joined: 20 years ago
Posts: 64
 

I've found that FTK Imager sometimes has trouble in mounting snapshots. Also, if you want to mount a Vista image, I suggest VDK or the vm-ware mount utility available in the developers kit, http//www.vmware.com/support/developer/vddk/. The mount function in the 6.x has trouble with Vista partitions.


   
ReplyQuote
Page 1 / 2
Share: