Forensics - Windows XP Live Forensics & Disk Acquisition

Опубликовано: 16 Февраль 2026
на канале: Attack404
124
4

In this episode we take a look at how to export a disk image from a live system, or an ESXi virtualized host. We demonstrate two ways that we can make / obtain a disk image. The methods discussed are as follows:

1) Boot the VM with a linux live and push the disk over ssh to a system we can perform the acquisition on (This can also be performed on a hardware device such as laptop, desktop or server not just a vm)

2) SSH into our VM host and acquire the VDI (VMWare Disk Image) and push it to a storage controller where we can import the image into a forensic tool of our choosing.

If you require a document to follow along to, please use the links below.

Acquisition Document & Command List:
Ubuntu Live ISO: https://ubuntu.com/download/desktop
Sleuth Kit: https://www.sleuthkit.org/sleuthkit/d...
NSRL (National Software Reference Library): https://www.nist.gov/itl/ssd/software...

Previous Video Part 1:    • Windows XP - Incident Response Part 1 #dfi...  
Previous Video Part 2:    • Windows XP - Incident Response Part 1 #dfi...  

#incidentresponse #dfir #digitalforensics #dd #forensicanalysis #autopsy #sleuthkit #computerforensics #infosecurity