Notifications
Clear all

Timeline - SIFT kit

4 Posts
3 Users
0 Reactions
926 Views
(@badnut)
New Member
Joined: 12 years ago
Posts: 4
Topic starter  

Timelining skills a little rusty -

Trying to mount either a compressed E01 (logical image of a C drive) using ewf_mount.py…OR…mount a RAW image (same logical image) using mount command.

I tried to run mmls and got 'cannot determine partition type'..any ideas anyone?


   
Quote
(@badgerau)
Trusted Member
Joined: 12 years ago
Posts: 96
 

This may be helpful

http//digital-forensics.sans.org/blog/2011/11/28/digital-forensic-sifting-mounting-ewf-or-e01-evidence-image-files


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Timelining skills a little rusty -

Trying to mount either a compressed E01 (logical image of a C drive) using ewf_mount.py…OR…mount a RAW image (same logical image) using mount command.

I tried to run mmls and got 'cannot determine partition type'..any ideas anyone?

mmls is run against an image, not a mounted image. When it's mounted, it's a volume.

mmls reads the partition table…a logical image is of a volume, and doesn't have a partition table.

HTH


   
ReplyQuote
(@badnut)
New Member
Joined: 12 years ago
Posts: 4
Topic starter  

Thank you - it does help.


   
ReplyQuote
Share: