Imaging of windows ...
 
Notifications
Clear all

Imaging of windows 10 Machine

3 Posts
3 Users
0 Reactions
945 Views
(@nikhilr)
New Member
Joined: 7 years ago
Posts: 1
Topic starter  

Hi,

I recently imaged one windows 10 machine using paladin Bootable pendrive. The system has a bios password which appears on the screen before booting. I have the password and booted successfully into the paladin interface and imaging done successfully. When i loaded the evidence into encase v8.07, it only shows unallocated partitions and system files. There is no user data present in encase.

I have emulated the whole image into virtual local disks using encase and there appears partitions in the form of local disks. I can see user data inside each disks.I loaded these disks as evidence in encase v8.07 and i can access the user data through encase.

But i don't know it is a forensically right procedure. Is there any other way that i can see the user data in encase without emulating the evidence?


   
Quote
(@dpathan)
Eminent Member
Joined: 7 years ago
Posts: 28
 

Can you post the screenshot of loaded evidence in encase that shows unallocated partition only. I am wondering if only a partition was added as evidence instead of an entire image.


   
ReplyQuote
(@zetaz)
Active Member
Joined: 13 years ago
Posts: 6
 

in fact, the drives you have mounted are "read only" so for me it's the same as working on a suspect drive with writeblocker. There is no problem for me


   
ReplyQuote
Share: