[How-To] Mount an Expert Witness File with EWFMount

preview_player
Показать описание
Learn how to mount an Expert Witness File in Linux using the tool EWFMount. EWFMount makes disk images in the Expert Witness Format (.E01) able to be accessed like an attached hard disk. Mounting the disk image allows you to use other tools and investigation methods against the data, even if that tool does not support EWF formats.

EWF images are a common file type used by Law Enforcement around the world. EWF has some additional features, such as compression and error checking, that you will not have with RAW (dd) disk images.

010001000100011001010011011000110110100101100101011011100110001101100101
Get more Digital Forensic Science

010100110111010101100010011100110110001101110010011010010110001001100101

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please link back to the original video. If you want to use this video for commercial purposes, please contact us first. We would love to see what you are doing.
Рекомендации по теме
Комментарии
Автор

Your voice is so charismatic, it makes it so easier to understand these difficult concepts

stephanieholland
Автор

Very good! A lot of tutorials run commands with out giving an explanation of them. Very beneficial!

hipmatt
Автор

When i do mmls it doesn't show anything?

joshuasnel
Автор

I tried this. 1. When I mount the image it changes the temp directory to root:root (555) even though I set it as username:username prior to the ewmount command. I can still go into the folder and see ewf1. I can fdisk it. I can mmls on it. But when I try to mount the file I can't create the loop even if I use sudo. baffled. You don't show that part in your video.

robertwoodruff
Автор

Very interesting thanks for your tutorial.
Does mounting require more steps if the ewf file is splited ?

Hyazoulephant
Автор

we can use mmls for that e01 at the first place i guess, how to extract files in that image?? like registry

nboi