VMDK File Analysis ...
 
Notifications
Clear all

VMDK File Analysis (sesparse.vmdk)

6 Posts
3 Users
0 Reactions
7,876 Views
(@cc4n6)
Eminent Member
Joined: 7 years ago
Posts: 18
Topic starter  

Hello All,

 

I received a few vmdk files for analysis. The files I was given are:

Server1-000001.vmdk

Server1-000001-sesparse.vmdk

Server1-000002.vmdk

Server1-000002-sesparse.vmdk

Any tool I try to open them with (FTK Imager and Axiom) fails. Has anyone dealt with these VM formats? I have no problems with flat VMDK files. Is there a conversion that needs to take place?

 

Any help is much appreciated!


   
Quote
 dega
(@dega)
Reputable Member
Joined: 11 years ago
Posts: 267
 

try with autopsy


   
ReplyQuote
(@cc4n6)
Eminent Member
Joined: 7 years ago
Posts: 18
Topic starter  

Autopsy did not like the VMDK's.

Back to the drawing board..


   
ReplyQuote
Henk
 Henk
(@tecleo)
Active Member
Joined: 5 years ago
Posts: 8

   
ReplyQuote
 dega
(@dega)
Reputable Member
Joined: 11 years ago
Posts: 267
 

@cc4n6 

sure? Here they talk about vmdk. You back to the drawing board 😛

https://sleuthkit.org/autopsy/docs/user-docs/4.19.1/ds_page.html

 


   
ReplyQuote
(@cc4n6)
Eminent Member
Joined: 7 years ago
Posts: 18
Topic starter  

@giandega The issue is the -sesparse.vmdk files   The applications do not like them. They might not be suitable for analysis.


   
ReplyQuote
Share: