Hi Sean,
You can compile it with visual studio express 2008. You do not have to pay for that version. Codegear support (formerly Borland C++) is in the making.
Kind regards,
RJM
Rich and David,
If you read the original post you'll note that I was asking specifically about ewfacquire to image shadow files with Windows FE. I want to try to use ewfacquire to attempt to do the same thing you would do with DD but send it straight to a compressed EWF image instead of an uncompressed DD image.
This being the case Guidance do not currently offer any software to do this. I know that I can use EnCase to take disk images but I was after a command line equivalent that I could use for experimentation with Vista shadow files. Hope this clears up the request.
I may have to look at the Visual Studio option unless someone has a binary available or unless I'm wrong and EnCase can indeed image Vista shadow files and I'm missing something obvious.
Except that you have to pay for Visual Studio twisted
How about
Paul
For everyone's information, I have successfully created ewfacquire for Windows systems. I'm going to attempt to use this to acquire Vista shadow volumes tomorrow morning. I'll let you know if I'm successful.
Great to hear that your F7-key is OK ;).
As I said… it compiles flawlessly!
In fairness, I needed to find some header files and a couple of additional files to make it work, but it seems fine. But thanks for the tip.
Get it at http//
sourceforge.net/projects/libewf/ The beta-version compiles flawlessly with Visual Studio 2008. No need for Cygwin anymore.
Except that you have to pay for Visual Studio twisted
Will Visual Studio Express compile what you need, that's free (or at least was)?
Compiled fine with Visual Studio C++ Express, but I needed to find a couple of extra header files and such.
You can also get Visual Studio 2008 Express edition for free
Or, download FAU (Forensic Acquisition Utilities) at http//
This works very well in the WinFE environment and it was the tool Troy Larson of Microsoft used to demonstrate imaging mounted shadow volumes.