Rochester Institute of Technology RIT Scholar Works Presentations and other scholarship Faculty & Staff choS larship 7-2012 Forensic Acquisition and Analysis of VMware Virtual Hard Disks Manish Hirwani Rochester Institute of Technology Yin Pan Rochester Institute of Technology Bill Stackpole Rochester Institute of Technology Daryl Johnson Rochester Institute of Technology Follow this and additional works at: https://scholarworks.rit.edu/other Recommended Citation Hirwani M., Pan Y. , Stackpole W., and Johnson D. Forensic Acquisition and Analysis of VMware Virtual Hard Disks. In SAM'12 - The 2012 International Conference on Security and Management (Las Vegas, NV, USA, July 2012) This Conference Paper is brought to you for free and open access by the Faculty & Staff choS larship at RIT Scholar Works. It has been accepted for inclusion in Presentations and other scholarship by an authorized administrator of RIT Scholar Works. For more information, please contact
[email protected]. Forensic Acquisition and Analysis of VMware Virtual Hard Disks Manish Hirwani, Yin Pan, Bill Stackpole and Daryl Johnson Networking, Security and Systems Administration Rochester Institute of Technology
[email protected]; {yin.pan; bill.stackpole; daryl.johnson}@it.rit.edu Abstract— With the advancement in virtualization VMware VMs are implemented using virtual adapters for technology, virtual machines (VMs) are becoming a devices such as network cards, memory, etc. The VM, common and integral part of datacenters. As the however, is stored in a set of files. VMware Workstation popularity and the use of VMs increases, incidents creates files with extension like virtual machine involving them are also on the rise. There is configuration (.vmx), virtual hard drive (.vmdk), snapshot substantial research on using VMs and virtual of the virtual machines’ memory appliances to aid forensic investigation, but research (.vmem) etc [18].