Advanced EnCase

Recover Partition

Mounting Evidence as VFS

Virtual File System (VFS) mounts a drive, volume or folder as read-only offline network share.

  1. Device > Share > Mount as Network Share

  2. Input Server Info, client info

Note: To stop the VFS service, double click “Virtual File System” in lower-right corner

Mount evidence as PDE

Mounting evidence by Physical Disk Emulation is like mounting the disk as an actual physical disk attached to the examiner machine.

This enables analysis of the evidence using other forensic tools, or use it to boot into a virtual machine. But this limits the supported file systems for casual browsing to those supported by windows (i.e. FAT & NTFS)

  1. Device > Share > Mount as Emulated Disk

  2. Selecting “Disable Cache” enables write-emulation, and changes are sent to cache folder (similar to mounting by FTK imager and Arsenal Image Mounter's "Write temporary disk device")

Booting it into a VM

Last updated