Malware detection s...
 
Notifications
Clear all

Malware detection software that can read images .dd, .raw, .E01

6 Posts
5 Users
0 Reactions
3,381 Views
(@cybertend)
Eminent Member
Joined: 6 years ago
Posts: 22
Topic starter  

Anyone know of any anti-malware/malware detection software that can be run against an image without mounting the image or otherwise modifying the image?


   
Quote
alanharper
(@alanharper)
New Member
Joined: 17 years ago
Posts: 3
 

If I may ask, what issue do you have with mounting since there a free and paid tools that will mount read only and protect the evidence?  OSF Mount, Arsenal Image Mounting and Mount Image Pro come to mind.


   
ReplyQuote
(@cybertend)
Eminent Member
Joined: 6 years ago
Posts: 22
Topic starter  

Agree, this is the approach 99% of the time.  However we are doing investigations against quite a number of servers and systems.  The images are going to a central repository where we hoped to use some tools on the images themselves.


   
ReplyQuote
Passmark
(@passmark)
Reputable Member
Joined: 14 years ago
Posts: 376
 

Having disk images in central repository doesn't stop you mounting the image.

You can also mount them from command line via script, or mount read only, or just duplicate  the image and work on the duplicate, to be really really over the top safe.

Working from central repository might make it rather slow to process however, as network latency & bandwidth is typically an order of worse than a local SSD. Better to do the job on a local drive and just use repository for long term archiving IMHO. 


   
ReplyQuote
(@aquachimere)
Eminent Member
Joined: 7 years ago
Posts: 32
 
Posted by: @cybertend

Anyone know of any anti-malware/malware detection software that can be run against an image without mounting the image or otherwise modifying the image?

Orange Malware Cleaner mount E01 files in order to analyse them.

 

https://www.orange-business.com/fr/produits/malware-cleaner

 

This post was modified 4 years ago by Aquachimere

   
ReplyQuote
(@belkasoft)
Estimable Member
Joined: 17 years ago
Posts: 169
 

Not specifically designed for this task, but there is a malware detection function in Belkasoft X.


   
ReplyQuote
Share: