VMDK File Analysis ...
 
Notifications
Clear all

VMDK File Analysis (sesparse.vmdk)

CC4n6
(@cc4n6)
New Member

Hello All,

 

I received a few vmdk files for analysis. The files I was given are:

Server1-000001.vmdk

Server1-000001-sesparse.vmdk

Server1-000002.vmdk

Server1-000002-sesparse.vmdk

Any tool I try to open them with (FTK Imager and Axiom) fails. Has anyone dealt with these VM formats? I have no problems with flat VMDK files. Is there a conversion that needs to take place?

 

Any help is much appreciated!

Quote
Topic starter Posted : 24/09/2021 7:00 pm
giandega
(@giandega)
Active Member

try with autopsy

ReplyQuote
Posted : 24/09/2021 10:45 pm
CC4n6
(@cc4n6)
New Member

Autopsy did not like the VMDK's.

Back to the drawing board..

ReplyQuote
Topic starter Posted : 27/09/2021 3:44 pm
Tecleo
(@tecleo)
New Member
giandega
(@giandega)
Active Member

@cc4n6 

sure? Here they talk about vmdk. You back to the drawing board 😛

https://sleuthkit.org/autopsy/docs/user-docs/4.19.1/ds_page.html

 

ReplyQuote
Posted : 27/09/2021 7:51 pm
CC4n6
(@cc4n6)
New Member

@giandega The issue is the -sesparse.vmdk files   The applications do not like them. They might not be suitable for analysis.

ReplyQuote
Topic starter Posted : 27/09/2021 8:41 pm
Share: