Ronald Godfrey
   Common in today’s computing environment
   Allow the user to run multiple, self contained
    operating systems on one hardware host
    machine
   The virtual machine utilizes the host
    machine’s resources (RAM, network
    interface, etc)
   Data can be transferred between the host
    and the virtual machine
Mounting virtual hard drives
   Microsoft Virtual PC – typically has a “*.vhd” hard
    drive extension
   Microsoft XP Mode - typically has a “*.vhd” hard
    drive extension
   Oracle Virtualbox - typically has a “*.vdi” hard drive
    extension
   VMWare - typically has a “*.vhd” or “vmdk” hard
    drive extension
   Virtual hard drive files are typically large in
    size.
   Usually two files are associated with the
    virtual machine
     Virtual hard drive file – contains the O/S and data
     Virtual machine settings file – provides the virtual
     machine’s configuration settings when used on
     the host machine
Mounting virtual hard drives
   FTK Imager 3.0 and newer versions have the
    ability to mount forensic images and virtual
    hard drives.
   Images can be mounted as mapped drives on
    the computer
   Physical virtual hard drives and their logical
    partitions can be mounted.
   Mounted by using the “FileImage Mounting”
    within FTK Imager
   Images can be mounted as “read only”
Mounting virtual hard drives
Mounting virtual hard drives
   If you mount the virtual hard drive and you
    see the “unrecognized file system”, use
    Virtualbox’s internal commands to convert
    the hard drive to a raw format.
Mounting virtual hard drives
   Extract the “vdi” file from the forensic image to a location
    on your hard drive:
     Open a command prompt window and navigate to the
      VirtualBox folder (typically c:Program FilesOracleVirtualBox).
     Run the following command against the “vdi” file you wish to
      convert (no quotes in the command line):
    vboxmanage.exe internalcommands converttoraw "xpath-to-
      vdi-filevdifilename.vdi" "x:path-to-output-
      foldervdifilename.raw“

   Conversion time will vary depending on the size of the
    “VDI file. It is recommended you have twice the amount of
    drive space available as is the size of the “vdi” file since
    you are converting to an uncompressed “raw” format.
Mounting virtual hard drives
Mounting virtual hard drives
Mounting virtual hard drives
Virtual hard drive
shows up as a
physical drive on
the system. The
drive can then be
imaged again and
compared via
hashing to ensure
everything was
captured.

More Related Content

PPTX
Incident response process
PPTX
Intrusion prevention system(ips)
PDF
Techowl- Wazuh.pdf
PPT
Network Administrator
PDF
Information Security Lecture Notes
PPT
Active directory
PPTX
Beginner's Guide to SIEM
PPTX
Open Cloud Consortium Overview (01-10-10 V6)
Incident response process
Intrusion prevention system(ips)
Techowl- Wazuh.pdf
Network Administrator
Information Security Lecture Notes
Active directory
Beginner's Guide to SIEM
Open Cloud Consortium Overview (01-10-10 V6)

What's hot (20)

PDF
Cloud-forensics
PDF
CNIT 121: 8 Forensic Duplication
PDF
data mining
PPTX
Steganography
PPSX
Cloud Forensics
PPTX
E-mail Investigation
PPTX
Footprinting and reconnaissance
PPTX
Computer forensics powerpoint presentation
PDF
Network Security Presentation
PPTX
Introduction to penetration testing
PPTX
Data Acquisition
PPTX
Windows Registry
PPTX
Data recovery
PDF
NTFS Forensics
PPTX
Guest Lecture-Computer and Cyber Security.pptx
PPTX
Unix operating system architecture with file structure
PPT
Module 3 Scanning
PPT
Windows forensic artifacts
Cloud-forensics
CNIT 121: 8 Forensic Duplication
data mining
Steganography
Cloud Forensics
E-mail Investigation
Footprinting and reconnaissance
Computer forensics powerpoint presentation
Network Security Presentation
Introduction to penetration testing
Data Acquisition
Windows Registry
Data recovery
NTFS Forensics
Guest Lecture-Computer and Cyber Security.pptx
Unix operating system architecture with file structure
Module 3 Scanning
Windows forensic artifacts
Ad

Viewers also liked (20)

PPT
Computer Forensics & Windows Registry
PPTX
NTFS vs FAT
PPT
Level1 Part8 End Of The Day
PDF
Sadfe2007
PDF
Windows 7-cheat-sheet
PPTX
Citrix
PPTX
Social Media Forensics for Investigators
PPT
Corporate Public Investigations
PPT
Nra
PPTX
Windows 7 forensics jump lists-rv3-public
PPTX
OSDF 2013 - Autopsy 3: Extensible Desktop Forensics by Brian Carrier
PPT
Registry forensics
PPT
Part6 Private Sector Concerns
PDF
www.indonezia.net Hacking Windows Registry
PPTX
Windows 10 Forensics: OS Evidentiary Artefacts
PPT
File system
PDF
Forensic Anaysis on Twitter
PDF
Accessioning-Based Metadata Extraction and Iterative Processing: Notes From t...
PPT
Installation of Joomla on Windows XP
Computer Forensics & Windows Registry
NTFS vs FAT
Level1 Part8 End Of The Day
Sadfe2007
Windows 7-cheat-sheet
Citrix
Social Media Forensics for Investigators
Corporate Public Investigations
Nra
Windows 7 forensics jump lists-rv3-public
OSDF 2013 - Autopsy 3: Extensible Desktop Forensics by Brian Carrier
Registry forensics
Part6 Private Sector Concerns
www.indonezia.net Hacking Windows Registry
Windows 10 Forensics: OS Evidentiary Artefacts
File system
Forensic Anaysis on Twitter
Accessioning-Based Metadata Extraction and Iterative Processing: Notes From t...
Installation of Joomla on Windows XP
Ad

Similar to Mounting virtual hard drives (20)

PDF
SysInternals Disk2vhd - docs.pdf
PPTX
Virtual Hard disk
PDF
Native VHD Boot: A Walkthrough of Common Scenarios
PPTX
Microsoft Windows Server 2012 R2 Hyper V server overview
PPTX
Upgrading and deploying Windows 7
PDF
Virtualization workshop - part 1
PDF
Virtualization And Disk Performance
PPT
VM.ppt
PPTX
2 Boot To Vhd
PPTX
Practical Implementation of Virtual Machine
PDF
Windows server 2012 r2 Hyper-v Component architecture
PPTX
Virtual Machines - Virtual Box
PDF
VHD Recovery Software
PDF
H: Drive
PDF
Running virtual box from the linux command line
ODP
VirtualBox Ubuntu Host Windows Guest
PPTX
Hyper-V overview and building test network - harold.wong
PPT
Virtualizing Testbeds For Fun And Profit
PDF
how to install VMware
SysInternals Disk2vhd - docs.pdf
Virtual Hard disk
Native VHD Boot: A Walkthrough of Common Scenarios
Microsoft Windows Server 2012 R2 Hyper V server overview
Upgrading and deploying Windows 7
Virtualization workshop - part 1
Virtualization And Disk Performance
VM.ppt
2 Boot To Vhd
Practical Implementation of Virtual Machine
Windows server 2012 r2 Hyper-v Component architecture
Virtual Machines - Virtual Box
VHD Recovery Software
H: Drive
Running virtual box from the linux command line
VirtualBox Ubuntu Host Windows Guest
Hyper-V overview and building test network - harold.wong
Virtualizing Testbeds For Fun And Profit
how to install VMware

More from CTIN (20)

PPTX
Open Source Forensics
PDF
Encase V7 Presented by Guidance Software august 2011
PDF
Windows 7 forensics -overview-r3
PDF
Windows 7 forensics event logs-dtl-r3
PPTX
Msra 2011 windows7 forensics-troyla
PPTX
Windows 7 forensics thumbnail-dtl-r4
PPTX
Time Stamp Analysis of Windows Systems
PPT
Vista Forensics
PPT
Mac Forensics
PPT
Live Forensics
PPT
Translating Geek To Attorneys It Security
PPT
Edrm
PPT
Computer Searchs, Electronic Communication, Computer Trespass
PPT
CyberCrime
PPT
Search Warrants
PPT
Raidprep
PPT
Networking Overview
PPT
M Compevid
PPT
L Scope
PPT
Law Enforcement Role In Computing
Open Source Forensics
Encase V7 Presented by Guidance Software august 2011
Windows 7 forensics -overview-r3
Windows 7 forensics event logs-dtl-r3
Msra 2011 windows7 forensics-troyla
Windows 7 forensics thumbnail-dtl-r4
Time Stamp Analysis of Windows Systems
Vista Forensics
Mac Forensics
Live Forensics
Translating Geek To Attorneys It Security
Edrm
Computer Searchs, Electronic Communication, Computer Trespass
CyberCrime
Search Warrants
Raidprep
Networking Overview
M Compevid
L Scope
Law Enforcement Role In Computing

Recently uploaded (20)

PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PPTX
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
PPT
Geologic Time for studying geology for geologist
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
A review of recent deep learning applications in wood surface defect identifi...
PDF
Developing a website for English-speaking practice to English as a foreign la...
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
STKI Israel Market Study 2025 version august
PPTX
Microsoft Excel 365/2024 Beginner's training
PPTX
Custom Battery Pack Design Considerations for Performance and Safety
PDF
Flame analysis and combustion estimation using large language and vision assi...
PPT
Module 1.ppt Iot fundamentals and Architecture
PPTX
The various Industrial Revolutions .pptx
PPT
What is a Computer? Input Devices /output devices
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
sbt 2.0: go big (Scala Days 2025 edition)
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
Enhancing emotion recognition model for a student engagement use case through...
Credit Without Borders: AI and Financial Inclusion in Bangladesh
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
Geologic Time for studying geology for geologist
OpenACC and Open Hackathons Monthly Highlights July 2025
A review of recent deep learning applications in wood surface defect identifi...
Developing a website for English-speaking practice to English as a foreign la...
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
NewMind AI Weekly Chronicles – August ’25 Week III
1 - Historical Antecedents, Social Consideration.pdf
STKI Israel Market Study 2025 version august
Microsoft Excel 365/2024 Beginner's training
Custom Battery Pack Design Considerations for Performance and Safety
Flame analysis and combustion estimation using large language and vision assi...
Module 1.ppt Iot fundamentals and Architecture
The various Industrial Revolutions .pptx
What is a Computer? Input Devices /output devices
A comparative study of natural language inference in Swahili using monolingua...
sbt 2.0: go big (Scala Days 2025 edition)

Mounting virtual hard drives

  • 2. Common in today’s computing environment  Allow the user to run multiple, self contained operating systems on one hardware host machine  The virtual machine utilizes the host machine’s resources (RAM, network interface, etc)  Data can be transferred between the host and the virtual machine
  • 4. Microsoft Virtual PC – typically has a “*.vhd” hard drive extension  Microsoft XP Mode - typically has a “*.vhd” hard drive extension  Oracle Virtualbox - typically has a “*.vdi” hard drive extension  VMWare - typically has a “*.vhd” or “vmdk” hard drive extension
  • 5. Virtual hard drive files are typically large in size.  Usually two files are associated with the virtual machine  Virtual hard drive file – contains the O/S and data  Virtual machine settings file – provides the virtual machine’s configuration settings when used on the host machine
  • 7. FTK Imager 3.0 and newer versions have the ability to mount forensic images and virtual hard drives.  Images can be mounted as mapped drives on the computer  Physical virtual hard drives and their logical partitions can be mounted.  Mounted by using the “FileImage Mounting” within FTK Imager
  • 8. Images can be mounted as “read only”
  • 11. If you mount the virtual hard drive and you see the “unrecognized file system”, use Virtualbox’s internal commands to convert the hard drive to a raw format.
  • 13. Extract the “vdi” file from the forensic image to a location on your hard drive:  Open a command prompt window and navigate to the VirtualBox folder (typically c:Program FilesOracleVirtualBox).  Run the following command against the “vdi” file you wish to convert (no quotes in the command line): vboxmanage.exe internalcommands converttoraw "xpath-to- vdi-filevdifilename.vdi" "x:path-to-output- foldervdifilename.raw“  Conversion time will vary depending on the size of the “VDI file. It is recommended you have twice the amount of drive space available as is the size of the “vdi” file since you are converting to an uncompressed “raw” format.
  • 17. Virtual hard drive shows up as a physical drive on the system. The drive can then be imaged again and compared via hashing to ensure everything was captured.