DFIR FTK Imager
Last updated
Last updated
Select source
Select Drive
Create Image
Select Image Type
Define the length of the segments or set it as "0" to create a single raw image.
The "/b" parameter means: binary.
If you can't change the SAM file or the login doesn't work, you can simply create a ISO file with the needed tools (e.g.: velociraptor collector) and execute it locally with Hiron's Boot.
Add the iso file via CD drive on virtualbox.
Use the dissect-shell after that to dump the outputed .zip file with all the artifacts .