VM Forensics

Stan J
Stan J used Ask the Experts™
on
In our test/dev lab we are running vSPhere 6.0, 6.5 and 6.7 on different platforms.

We are looking into how to perform forensics on VMs (OVFs, Snapshots, etc.) off line.

Does anyone know of any products in the VMware portfolio or partner products that may be a good option for this use case?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Top Expert 2016

Commented:
Forensics on a virtual disk is exactly the same as with a physical disk.
It's actually a bit easier since it's already a file that you can more easily "clone" and back up without having to pull out disks.
Stan JVirtualization Engineer

Author

Commented:
thanks,,,can you provide examples or tools on the best approach to do the forensics

Commented:
Encase and FTK are common.
Stan JVirtualization Engineer

Author

Commented:
thanks for these tips....

We use Veeam and have VAS.

The Enterprise and Enterprise Plus options provide a tool called DataLabs (sandbox) that also may be used in conjunction with tools

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial