Solved

Windows: Getting forensic image from truecrypt container (opened) and getting forensic image from nonopened truecrypt container

Posted on 2010-08-25
3
573 Views
Last Modified: 2012-06-27
Hello,

i would like to know to to get a dd image from truecrypt container which is allready mounted

AND

i would like to know how to get it when the file is not mounted.

My environment is a windows box. All Solutions should be freeware.

regards

bytes
0
Comment
Question by:ByteSleuth
  • 2
3 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 33521151
to get it while mounted:

download and unzip http://www.chrysocome.net/dd

use the command dd if=\\.\k: of=drive.img bs=10M

where k: is the drive it is mounted on (change to suit)
drive.img is the target file (must be enough space to store an uncompressed image of the drive)
and 10M is the buffer (chunk) size during the copy - larger sizes mean faster copies, but more memory used.

to get it while not mounted:

just copy the file :)
0
 
LVL 5

Author Comment

by:ByteSleuth
ID: 33521223
Hello

thanks a lot :-)

Here are your points...
0
 
LVL 5

Author Closing Comment

by:ByteSleuth
ID: 33521233
Thanks a lot buddy.
View my other questions about truecrypt-----
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

You cannot be 100% sure that you can protect your organization against crypto ransomware but you can lower down the risk and impact of the infection.
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now