Forensic image booting in VirtualBox with FTK Imager

4 years ago
21

In this episode, we will walk through how to take a forensic copy of a hard drive, make a copy with FTK Imager, convert the image to a .vmdk file with VBoxManage, and boot it in a virtual machine with VirtualBox.

This is useful for forensic investigations, DFIR, malware analysis, and even data recovery.

If you would like to support our channel and content, we have printed/ebook publications with in depth on Amazon [https://amzn.to/3nL9RsC] and merch on Teespring [https://teespring.com/stores/cybersec...]

Loading comments...