Link to home
Create AccountLog in
Avatar of Stan J
Stan JFlag for United States of America

asked on

VM Forensics

In our test/dev lab we are running vSPhere 6.0, 6.5 and 6.7 on different platforms.

We are looking into how to perform forensics on VMs (OVFs, Snapshots, etc.) off line.

Does anyone know of any products in the VMware portfolio or partner products that may be a good option for this use case?
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

Forensics on a virtual disk is exactly the same as with a physical disk.
It's actually a bit easier since it's already a file that you can more easily "clone" and back up without having to pull out disks.
Avatar of Stan J


thanks,,,can you provide examples or tools on the best approach to do the forensics
Avatar of serialband
Flag of Ukraine image

Link to home
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Pau Lo
Pau Lo

Encase and FTK are common.
Avatar of Stan J


thanks for these tips....

We use Veeam and have VAS.

The Enterprise and Enterprise Plus options provide a tool called DataLabs (sandbox) that also may be used in conjunction with tools