Mounting File Systems

File Location:

Parse Data

#Mounting E01 Images 
ewfmount image.E01 mountpoint

mount –o loop,ro,show_sys_files,streams_interface=windows /mnt/ewf/ewf1 /mnt/windows_mount


#### Mounting Volume Shadow Copies ####

#Stage 1 – Attach local or remote system drive
ewfmount system-name.E01 /mnt/ewf

#Stage 2 – Mount raw image VSS
vshadowmount ewf1 /mnt/vss/

#Stage 3 – Mount all logical filesystem of snapshot
cd /mnt/vss for i in vss*; do mount -o ro,loop,show_sys_files,streams_interface=windows $i /mnt/shadow_mount/$i; done 

Scanning File System

Considerations

Anti-Forensics

Last updated