I will 3rd using FTK imager to conver to raw. Let us know how that goes.
Thanks,
Andrew (@attrc)
On 08/16/2016 12:54 PM, Jared Greenhill wrote:Bridgey,I haven't been in this EWF situation for memory yet but I'd probably tryimagecopy first:vol.exe -f image.e01 --profile=<yourprofile> -O image.rawIf that didn't work, I'd use Tom's #2 and load the .E01 in FTK imagerand image that mounted volume.If that didn't work I'd try load the evidence into encase 7.x - rightclick on the evidence --> evidence --> device --> share --> Mount asEmulated Disk and then use FTK imager to image that mounted volume to .rawJGOn Tue, Aug 16, 2016 at 11:03 AM, Tom Yarrish <tom@yarrish.com<mailto:tom@yarrish.com>> wrote:IIRC volatility should be able to handle an E01 file natively now(unless that's a *nix only thing). But another option would beeither 1) Arsenal Image Mounter (which works much better than FTK,EnCase, etc IMO) or 2) Use FTK to covert the E01 image to a RAWimage file and then just run that through volatility.Thanks,TomPGP Key ID - B32585D0On Tue, Aug 16, 2016 at 2:39 PM, Bridgey theGeek<bridgeythegeek@gmail.com <mailto:bridgeythegeek@gmail.com>> wrote:Hi all,Because the universe hates me, I've been given an E01 of a RAMdump (from Win7SP1x64) and I have to use Windows to run Volatility.I have p99 of tAoMF in front of me.I tried the "Mount in FTK Imager and point to Z:\unallocatedspace" thing, but pslist showed only 1 entry which looked verycorrupt.I don't have access to EnCase to mount it from there.So I'd like to use libewf. But can I even use it on Windows?? IfI compile the library, how do I tell Volatility about thelibewf.dll?Basically, how do I use Volatility with libewf on Windows?Thank you,Adam_______________________________________________Vol-users mailing listVol-users@volatilityfoundation.org <mailto:Vol-users@volatilityfoundation.org>http://lists.volatilityfoundation.org/mailman/listinfo/vol-users<http://lists.volatilityfoundation.org/mailman/listinfo/vol-users>_______________________________________________Vol-users mailing listVol-users@volatilityfoundation.org <mailto:Vol-users@volatilesystems.com>http://lists.volatilityfoundation.org/mailman/listinfo/vol-users<http://lists.volatilityfoundation.org/mailman/listinfo/vol-users>_______________________________________________Vol-users mailing listVol-users@volatilityfoundation.orghttp://lists.volatilityfoundation.org/mailman/listinfo/vol-users_______________________________________________
Vol-users mailing list
Vol-users@volatilityfoundation.org
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users