Notifications
Clear all

E01 files in Linux

7 Posts
3 Users
0 Reactions
1,653 Views
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
Topic starter  

Hi,

I am taking my first steps in Helix Forensics, and I've got a question. I've always made my analyses with EnCase, and hence all my evidence files are E0x files. Is there a way to open those evidence files with any Helix tool?

Thank you!


   
Quote
(@marat)
Eminent Member
Joined: 19 years ago
Posts: 31
 

You can use PyFLAG.
Best Regards.


   
ReplyQuote
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
Topic starter  

Ok! That's a good idea, but… how am I supposed to load an image? I tried to load a file, but PyFlag just looks for the file in a very specific path. How can be this predefined path be changed?

Thanks


   
ReplyQuote
(@lojack)
New Member
Joined: 19 years ago
Posts: 1
 

Hi,

I am taking my first steps in Helix Forensics, and I've got a question. I've always made my analyses with EnCase, and hence all my evidence files are E0x files. Is there a way to open those evidence files with any Helix tool?

Thank you!

Grab AccessData's imager, called FTK Imager. They provide it for free. (Thanks AD!) Use it to convert your E0* files to raw bitstream then use whatever tool you want, whether from Helix or otherwise.
[ http// w w w.accessdata.com/support/downloads/ ]


cms


   
ReplyQuote
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
Topic starter  

Well… that is an interesting hint… but now I am mainly interested in learning how to use PyFlag… and I cannot see where its configuration files are!!! Unless I find them, I wont be able to change the default path for the images. I have also tried to make a symbolic link in the default directory to the images files in my USB Hard Drive… ant does not work either


   
ReplyQuote
(@marat)
Eminent Member
Joined: 19 years ago
Posts: 31
 

May 11, 2006 Version 2.04 of The Sleuth Kit was released. It includes support for Expert Witness and AFF file formats, the ISO 9660 file system, and other new features


   
ReplyQuote
iruiper
(@iruiper)
Estimable Member
Joined: 19 years ago
Posts: 145
Topic starter  

Just in case someone needs this information in the future the configuration file which must be changed is .pyflagrc

Regards.


   
ReplyQuote
Share: