LiveView - Work with imaged drives on VMware

oliver writes over on assa’s blog on this cool new tool. it allows you to work with images, such as those created using dd, in vmware!

http://blog.assarbad.net/20060829/interesting-new-forensic-tool/

today the software engineering institute of the carnegie mellon university (cmu) announced a new tool named liveview on the forensics mailing list at security focus.

this tools looks really promising in that it claims to provide a way to create a vmware image from a physical disk or raw disk image (e.g. created with dd). such a tool will allow security researchers to inspect an infected machine without having to be at the site of the incident. although cmu introduced the tool to forensics specialists, it can be used in various ways apart from the main objective. such a tool should have been published long ago by the vm vendors. thank cert and cmu we now have this tool to aid in different ways during an investigation of malware targets.

check it out!

check it out! indeed!

gadi evron,
ge@beyondsecurity.com.

DiggRedditSlashdotTwitThisSphinnStumbleUpondel.icio.usFacebookGoogleTechnoratiE-mail this story to a friend!

-

Find security holes before hackers do. Sign up for a Vulnerability Assessment now!

Comments are closed.


Vulnerability Scanner