Has anyone been able to analyze the new VHDx images used by Windows 8/Server 2012 using a Windows 7 computer?
EnCase, FTK, X-Ways cannot analyze it.
Mount Image Pro cannot mount it.
From what I've read so far, I have 2 solutions
- Convert the VHDx image to VHD.
- Using Windows 8 Disk Manager, mount the VHDx file (read-only) then image the content of the mounted VHDx file.
The problem is that all my analysis machines are running Windows 7 so I would like to avoid, if possible, having to use Windows 8 on my analysis machine.
Thanks.
What about building a Win8 VM using Virtual Box or VMWare? You could build a small one to suit your needs and then dump it when you are done.
From what I've read so far, I have 2 solutions
- Convert the VHDx image to VHD.
- Using Windows 8 Disk Manager, mount the VHDx file (read-only) then image the content of the mounted VHDx file.
3rd possibility
mount it in a Qemu VM (read only)
http//
http//
You will need to check if also the Windows version has this possibility.
Virtualbox should also have that support (still read only).
jaclaz