DFIR FTK Imager

FTK Image Create

  1. Select source

  1. Select Drive

  2. Create Image

  3. Select Image Type

  1. Define the length of the segments or set it as "0" to create a single raw image.

Convert segments into a single raw file (dd)

The "/b" parameter means: binary.

Convert from E01 files into single RAW file

Convert from VMDK into RAW format with qemu

Convert from RAW format into VDI (VirtualBox)

Change SAM Password to boot machines

kon-bootCD-2.7.iso

cd140201.iso

17MB
Open

Hirens' Boot

Can not you login after patch the SAM?

If you can't change the SAM file or the login doesn't work, you can simply create a ISO file with the needed tools (e.g.: velociraptor collector) and execute it locally with Hiron's Boot.

Add the iso file via CD drive on virtualbox.

Use the dissect-shell after that to dump the outputed .zip file with all the artifacts .

Last updated

Was this helpful?