VMDK File Analysis ...
 
Notifications
Clear all

VMDK File Analysis (sesparse.vmdk)

6 Posts
3 Users
0 Reactions
9,083 Views
(@cc4n6)
Eminent Member
Joined: 8 years ago
Posts: 18
Topic starter   [#19248]

Hello All,

 

I received a few vmdk files for analysis. The files I was given are:

Server1-000001.vmdk

Server1-000001-sesparse.vmdk

Server1-000002.vmdk

Server1-000002-sesparse.vmdk

Any tool I try to open them with (FTK Imager and Axiom) fails. Has anyone dealt with these VM formats? I have no problems with flat VMDK files. Is there a conversion that needs to take place?

 

Any help is much appreciated!



   
Quote
 dega
(@dega)
Reputable Member
Joined: 12 years ago
Posts: 267
 

try with autopsy



   
ReplyQuote
(@cc4n6)
Eminent Member
Joined: 8 years ago
Posts: 18
Topic starter  

Autopsy did not like the VMDK's.

Back to the drawing board..



   
ReplyQuote
Henk
 Henk
(@tecleo)
Active Member
Joined: 6 years ago
Posts: 8

   
ReplyQuote
 dega
(@dega)
Reputable Member
Joined: 12 years ago
Posts: 267
 

@cc4n6 

sure? Here they talk about vmdk. You back to the drawing board 😛

https://sleuthkit.org/autopsy/docs/user-docs/4.19.1/ds_page.html

 



   
ReplyQuote
(@cc4n6)
Eminent Member
Joined: 8 years ago
Posts: 18
Topic starter  

@giandega The issue is the -sesparse.vmdk files   The applications do not like them. They might not be suitable for analysis.



   
ReplyQuote
Share: