{"id":129,"date":"2014-11-11T14:50:38","date_gmt":"2014-11-11T13:50:38","guid":{"rendered":"http:\/\/blog.ec35.de\/?p=129"},"modified":"2015-11-22T21:09:18","modified_gmt":"2015-11-22T20:09:18","slug":"arsenal-image-mounter-virtualisierung-von-e01-imagen","status":"publish","type":"post","link":"http:\/\/blog.ec35.de\/?p=129","title":{"rendered":"Arsenal Image Mounter  Virtualisierung von E01 Imagen"},"content":{"rendered":"<p><span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"http:\/\/blog.ec35.de\/?p=1044\">Update vorhanden!<\/a><\/span><\/p>\n<p>Seit dem Erscheinen von Arsenal Image Mounter gibt es eine weitere M\u00f6glichkeit ein E01 Image zu virtualisieren und gleichzeitig eine .vmdk zu erstellen, die nicht mehr auf das Image angewiesen ist. In diesem Beispiel wurde ein Win 8.1 Image verwendet.<\/p>\n<p>Ben\u00f6tigte Software:<\/p>\n<p>Arsenal Image Mounter: <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"http:\/\/arsenalrecon.com\/apps\/image-mounter\/\" target=\"_blank\">http:\/\/arsenalrecon.com\/apps\/image-mounter\/<\/a><\/span><\/p>\n<p>Paragon Virtualisierungstool z.B. Go Virtual 14 ( oder \u00e4hnliche Software, hier Kosten: 16,00 Euro)<\/p>\n<p><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/www.paragon-software.de\/de\/home\/go-virtual\/\" target=\"_blank\"> https:\/\/www.paragon-software.de\/de\/home\/go-virtual\/<\/a><\/span><\/p>\n<p>Installieren von AIM. Hierbei wird jetzt ein zus\u00e4tzlicher SCSI-Treiber installiert, der die Besonderheit von dem Tool ausmacht.<\/p>\n<p>Mit Admin-Rechten die \u201eMountTool.exe starten.<\/p>\n<p><a href=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg\" target=\"_blank\"><img data-attachment-id=\"130\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=130\" data-orig-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg?fit=604%2C365\" data-orig-size=\"604,365\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"aim1\" data-image-description=\"\" data-medium-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg?fit=300%2C181\" data-large-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg?fit=604%2C365\" loading=\"lazy\" class=\"aligncenter wp-image-130 size-medium\" src=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg?resize=300%2C181\" alt=\"aim1\" width=\"300\" height=\"181\" srcset=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg?resize=300%2C181 300w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim1.jpg?w=604 604w\" sizes=\"(max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>F\u00fcr gesplittete E01 Image ist diese Auswahl zu treffen.<\/p>\n<p>Das Image wird \u201ewriteable\u201c eingebunden.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg\" target=\"_blank\"><img data-attachment-id=\"131\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=131\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg?fit=560%2C434\" data-orig-size=\"560,434\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"aim3\" data-image-description=\"\" data-medium-file=\"https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg?fit=300%2C232\" data-large-file=\"https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg?fit=560%2C434\" loading=\"lazy\" class=\"alignnone wp-image-131 size-medium\" src=\"https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg?resize=300%2C232\" alt=\"aim3\" width=\"300\" height=\"232\" srcset=\"https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg?resize=300%2C232 300w, https:\/\/i0.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim3.jpg?w=560 560w\" sizes=\"(max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>Der Mounter h\u00e4ngt immer sowohl logisch, als auch physikalisch ein.<\/p>\n<p>Wie aber auch zu erkennen ist, wird das Image als Datentr\u00e4ger unter der Systemverwaltung von Windows erkannt.<\/p>\n<p><a href=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg\" target=\"_blank\"><img data-attachment-id=\"137\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=137\" data-orig-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?fit=778%2C427\" data-orig-size=\"778,427\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"aim5\" data-image-description=\"\" data-medium-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?fit=300%2C164\" data-large-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?fit=625%2C343\" loading=\"lazy\" class=\"alignnone wp-image-137 size-medium\" src=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?resize=300%2C164\" alt=\"aim5\" width=\"300\" height=\"164\" srcset=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?resize=300%2C164 300w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?resize=624%2C342 624w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim5.jpg?w=778 778w\" sizes=\"(max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>Dies ist der entscheidende Unterschied zu FTK-Imager, weil jetzt auch andere Programme den Datentr\u00e4ger interpretieren k\u00f6nnen.<\/p>\n<p>Weiterer Effekt ist, dass z.B. beim logischen Mounten von einem Bitlocker-Laufwerk eine Abfrage zum Eingeben des Schl\u00fcssels gemacht wird. Sehr interessant f\u00fcr XWays-User.<\/p>\n<p><a href=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg\" target=\"_blank\"><img data-attachment-id=\"133\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=133\" data-orig-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?fit=846%2C472\" data-orig-size=\"846,472\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"aim4\" data-image-description=\"\" data-medium-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?fit=300%2C167\" data-large-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?fit=625%2C349\" loading=\"lazy\" class=\"aligncenter wp-image-133\" src=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?resize=404%2C225\" alt=\"aim4\" width=\"404\" height=\"225\" srcset=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?resize=300%2C167 300w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?resize=624%2C348 624w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/aim41.jpg?w=846 846w\" sizes=\"(max-width: 404px) 100vw, 404px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>Paragon Go Virtual 14 starten.<\/p>\n<p>Hier ist das Image als Arsenal Virtual Device auszuw\u00e4hlen, einschlie\u00dflich aller Partitionen<\/p>\n<p><a href=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg\" target=\"_blank\"><img data-attachment-id=\"134\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=134\" data-orig-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?fit=694%2C475\" data-orig-size=\"694,475\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"para2\" data-image-description=\"\" data-medium-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?fit=300%2C205\" data-large-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?fit=625%2C428\" loading=\"lazy\" class=\"alignnone wp-image-134 size-medium\" src=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?resize=300%2C205\" alt=\"para2\" width=\"300\" height=\"205\" srcset=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?resize=300%2C205 300w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?resize=624%2C427 624w, https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para2.jpg?w=694 694w\" sizes=\"(max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>Durch die wenigen Einstellungen klicken.<\/p>\n<p>Das Image wird jetzt virtualisiert.<\/p>\n<p>Eine .vmdk wird geschrieben.<\/p>\n<p>Eine .vmx wird geschrieben und angepasst.<\/p>\n<p><a href=\"https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg\" target=\"_blank\"><img data-attachment-id=\"135\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=135\" data-orig-file=\"https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?fit=692%2C379\" data-orig-size=\"692,379\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"para6\" data-image-description=\"\" data-medium-file=\"https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?fit=300%2C164\" data-large-file=\"https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?fit=625%2C342\" loading=\"lazy\" class=\"aligncenter wp-image-135\" src=\"https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?resize=533%2C291\" alt=\"para6\" width=\"533\" height=\"291\" srcset=\"https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?resize=300%2C164 300w, https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?resize=624%2C341 624w, https:\/\/i2.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/para6.jpg?w=692 692w\" sizes=\"(max-width: 533px) 100vw, 533px\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>Damit ist die VM laufbereit.<\/p>\n<p>Wir m\u00fcssen jetzt nur noch die VM an unsere Bed\u00fcrfnisse anpassen:<\/p>\n<p>Netzwerk trennen<\/p>\n<p>Tools instalieren<\/p>\n<p>Benutzer zur\u00fccksetzen<\/p>\n<p>etc.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/vmx_win81.jpg\" target=\"_blank\"><img data-attachment-id=\"136\" data-permalink=\"http:\/\/blog.ec35.de\/?attachment_id=136\" data-orig-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/vmx_win81.jpg?fit=417%2C569\" data-orig-size=\"417,569\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"vmx_win81\" data-image-description=\"\" data-medium-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/vmx_win81.jpg?fit=219%2C300\" data-large-file=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/vmx_win81.jpg?fit=417%2C569\" loading=\"lazy\" class=\"aligncenter wp-image-136\" src=\"https:\/\/i1.wp.com\/blog.ec35.de\/wp-content\/uploads\/2014\/11\/vmx_win81.jpg?resize=332%2C455\" alt=\"vmx_win81\" width=\"332\" height=\"455\" data-recalc-dims=\"1\" \/><\/a><\/p>\n<p>Also gar nicht schlecht diese Variante. Bei einem sehr gro\u00dfen Image, welches nur von uns selbst virtuell ausgewertet werden soll, bietet es sich an, das Image nur einzuh\u00e4ngen und die .vmx selbst zu ver\u00e4ndern, um die VM lauff\u00e4hig zu machen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Update vorhanden! Seit dem Erscheinen von Arsenal Image Mounter gibt es eine weitere M\u00f6glichkeit ein E01 Image zu virtualisieren und gleichzeitig eine .vmdk zu erstellen, die nicht mehr auf das Image angewiesen ist. In diesem Beispiel wurde ein Win 8.1 Image verwendet. Ben\u00f6tigte Software: Arsenal Image Mounter: http:\/\/arsenalrecon.com\/apps\/image-mounter\/ Paragon Virtualisierungstool z.B. Go Virtual 14 ( [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[5],"tags":[],"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/p5bxlZ-25","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"http:\/\/blog.ec35.de\/index.php?rest_route=\/wp\/v2\/posts\/129"}],"collection":[{"href":"http:\/\/blog.ec35.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.ec35.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.ec35.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.ec35.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=129"}],"version-history":[{"count":4,"href":"http:\/\/blog.ec35.de\/index.php?rest_route=\/wp\/v2\/posts\/129\/revisions"}],"predecessor-version":[{"id":1058,"href":"http:\/\/blog.ec35.de\/index.php?rest_route=\/wp\/v2\/posts\/129\/revisions\/1058"}],"wp:attachment":[{"href":"http:\/\/blog.ec35.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.ec35.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=129"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.ec35.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}