Forensic image booting in VirtualBox with FTK Imager

Published December 13, 2020 1 Views

Rumble In this episode, we will walk through how to take a forensic copy of a hard drive, make a copy with FTK Imager, convert the image to a .vmdk file with VBoxManage, and boot it in a virtual machine with VirtualBox.

This is useful for forensic investigations, DFIR, malware analysis, and even data recovery.

