DFIR FTK Imager
Last updated
Was this helpful?
Last updated
Was this helpful?
Select source
Select Drive
Create Image
Select Image Type
Define the length of the segments or set it as "0" to create a single raw image.
The "/b" parameter means: binary.
If you can't change the SAM file or the login doesn't work, you can simply create a ISO file with the needed tools (e.g.: velociraptor collector) and execute it locally with Hiron's Boot.
Add the iso file via CD drive on virtualbox.
Use the dissect-shell after that to dump the outputed .zip file with all the artifacts .