# File Analysis

[**peepdf**](https://github.com/jesparza/peepdf) – PDF analyzer.

**oledump** – Windows file analysis \[[1](https://didierstevens.com/files/software/oledump_V0_0_41.zip)] and \[[2](https://blog.didierstevens.com/programs/oledump-py/)].

[**oletools**](http://www.decalage.info/python/oletools) – Suite to analyze OLE and MS Office files.

[**Structured Storage Viewer (SSV)**](https://www.mitec.cz/ssv.html) – This tool allows to completely manage any MS OLE Structured Storage based file.

[**BiffView**](https://www.aldeid.com/wiki/BiffView)**++** – BiffView is a tool for viewing the BIFF structure of a binary Excel sheet.

{% embed url="<https://github.com/sharkdp/binocle>" %}

[**Disk2vhd**](https://learn.microsoft.com/en-us/sysinternals/downloads/disk2vhd): Convert something to VHD to import in VirtualBox (e.g., nvme ssd). For Virtualbox, uncheck the option: "**use vhdx**".

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2F7L5H8OJJa9z0YkKkVxD4%2Fimage.png?alt=media&#x26;token=4ee7964b-dbbb-4bf9-b27a-4440eccc113f" alt=""><figcaption></figcaption></figure>

For cloning it, select all devices and partitions:

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2FLtU0glFFHk3gUbf0ScfC%2Fimage.png?alt=media&#x26;token=bfee8fef-636c-443b-97e8-f8981047f33e" alt=""><figcaption></figcaption></figure>

In VirtualBox, attach a new optical device:

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2F7YarqqghWxZOU8V8vQjM%2Fimage.png?alt=media&#x26;token=cabdbcfe-5460-4ca8-9ef8-883e2c0e0cb4" alt=""><figcaption></figcaption></figure>

Execute the **chntpw** with the virtual machine, and set the Administrator password as BLANK.

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2FTOEVJZxsn4tIxyjFEtPK%2Fimage.png?alt=media&#x26;token=80ea9d10-144a-4b21-ab47-593ad73c2950" alt=""><figcaption></figcaption></figure>

Option: 1

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2FYlHULLvdl2FwZc9vQKgh%2Fimage.png?alt=media&#x26;token=40204c44-8b73-436a-9604-29ac63e1fd0d" alt=""><figcaption></figcaption></figure>

Option: 1

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2F1xUOxnxEHpRl30ZOVau4%2Fimage.png?alt=media&#x26;token=2af78442-fc92-465b-aa47-89a73ad9d9a2" alt=""><figcaption></figcaption></figure>

Option: 1

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2Fjlk6IEHaKgGN6rU06kZp%2Fimage.png?alt=media&#x26;token=86e83cb7-c0e1-4b4e-8fc5-07a49b5da11f" alt=""><figcaption></figcaption></figure>

Option: 1f4

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2FG6VFnpr51cJKuMCll0Hf%2Fimage.png?alt=media&#x26;token=3e3b3842-8fd8-438c-9148-406ed7b76562" alt=""><figcaption></figcaption></figure>

Option: 1

After that, detach the optical drive, and restart the VM!

Using dd:

<figure><img src="https://4052868066-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWd-VcvRHVgUtkahm85%2Fuploads%2FuhHwgt4jJxZBYHZRM9Te%2Fimage.png?alt=media&#x26;token=ffe0654f-359c-4709-b46f-b15b89262f63" alt=""><figcaption></figcaption></figure>

```
dd if=/dev/sda1 of=/ruta/diskbak.raw
VBoxManage convertfromraw diskbak.raw --format vdi diskbak.vdi
VBoxManage modifyhd --compact diskbak.vdi

https://www.maravento.com/2013/11/clonacion-virtual-incremental.html
```
