Plaso
How to process an image using log2timeline/plaso
Verify E01 image using ewfacquire
$ sudo apt install ewf-tools
user@df:~/cases/26038642$ ls -lah
total 11G
drwxrwxr-x 2 user user 4.0K Jul 7 11:37 .
drwxrwxr-x 3 user user 4.0K Jul 7 11:36 ..
-rw-rw-r-- 1 user user 1.5G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E01
-rw-rw-r-- 1 user user 1.5G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E02
-rw-rw-r-- 1 user user 1.5G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E03
-rw-rw-r-- 1 user user 1.5G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E04
-rw-rw-r-- 1 user user 1.5G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E05
-rw-rw-r-- 1 user user 1.5G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E06
-rw-rw-r-- 1 user user 1.4G Jul 5 12:04 20240212-decrypted-Windows_Server_2022.E07user@df:~/cases/26038642$ ewfverify 20240212-decrypted-Windows_Server_2022.E01
ewfverify 20140807
Verify started at: Jul 07, 2024 12:11:05
This could take a while
Verify completed at: Jul 07, 2024 12:17:48
Read: 50 GiB (53687091200 bytes) in 6 minute(s) and 43 second(s) with 127 MiB/s (133218588 bytes/second).
MD5 hash stored in file: 9a982399621826a66ff322cc87376e76
MD5 hash calculated over data: 9a982399621826a66ff322cc87376e76
ewfverify: SUCCESSSetup and use log2timeline/plaso in Docker

Last updated