In this episode we take a look at how to export a disk image from a live system, or an ESXi virtualized host. We demonstrate two ways that we can make / obtain a disk image. The methods discussed are as follows:
1) Boot the VM with a linux live and push the disk over ssh to a system we can perform the acquisition on (This can also be performed on a hardware device such as laptop, desktop or server not just a vm)
2) SSH into our VM host and acquire the VDI (VMWare Disk Image) and push it to a storage controller where we can import the image into a forensic tool of our choosing.
If you require a document to follow along to, please use the links below.
Acquisition Document & Command List:
Ubuntu Live ISO: https://ubuntu.com/download/desktop
Sleuth Kit: https://www.sleuthkit.org/sleuthkit/d...
NSRL (National Software Reference Library): https://www.nist.gov/itl/ssd/software...
Previous Video Part 1: • Windows XP - Incident Response Part 1 #dfi...
Previous Video Part 2: • Windows XP - Incident Response Part 1 #dfi...
#incidentresponse #dfir #digitalforensics #dd #forensicanalysis #autopsy #sleuthkit #computerforensics #infosecurity