Hello All,
Â
I received a few vmdk files for analysis. The files I was given are:
Server1-000001.vmdk
Server1-000001-sesparse.vmdk
Server1-000002.vmdk
Server1-000002-sesparse.vmdk
Any tool I try to open them with (FTK Imager and Axiom) fails. Has anyone dealt with these VM formats? I have no problems with flat VMDK files. Is there a conversion that needs to take place?
Â
Any help is much appreciated!
try with autopsy
Autopsy did not like the VMDK's.
Back to the drawing board..
You try:
(1) Arsenal image mounter
https://arsenalrecon.com/products
(2) http://www.ufsexplorer.com
https://www.ufsexplorer.com/solutions/virtual-machine-data-recovery.php
See also:
You want me to deal with how many VMDKs!?
https://thinkdfir.com/2021/06/03/you-want-me-to-deal-with-how-many-vmdks/
sure? Here they talk about vmdk. You back to the drawing board 😛
https://sleuthkit.org/autopsy/docs/user-docs/4.19.1/ds_page.html
Â
@giandega The issue is the -sesparse.vmdk files  The applications do not like them. They might not be suitable for analysis.