Mounting File Systems
File Location:
Parse Data
#Mounting E01 Images
ewfmount image.E01 mountpoint
mount –o loop,ro,show_sys_files,streams_interface=windows /mnt/ewf/ewf1 /mnt/windows_mount
#### Mounting Volume Shadow Copies ####
#Stage 1 – Attach local or remote system drive
ewfmount system-name.E01 /mnt/ewf
#Stage 2 – Mount raw image VSS
vshadowmount ewf1 /mnt/vss/
#Stage 3 – Mount all logical filesystem of snapshot
cd /mnt/vss for i in vss*; do mount -o ro,loop,show_sys_files,streams_interface=windows $i /mnt/shadow_mount/$i; done Scanning File System
Considerations
Anti-Forensics
Last updated