v3.10.262
Released: 10-02-2023
Free Mode:
General
Professional Mode:
Launch VM
Improved recovery of deleted, locked out, disabled, and/or expired Windows accounts
Boot with last Windows shutdown time can now be adjusted to any valid date and time
Recovered passwords and PINs always displayed in AIM Virtual Machine Tools (regardless of bypass settings)
Improved quick DPAPI bypass when encountering partially corrupt data
Improved identification of open files before launching a VM
Expanded support for lvm/lvm2 volumes
Fixed error caused by launching a VM from a disk image not mounted by current AIM session
Windows file system driver bypass
Arsenal-Image-Mounter-v3.10.262.zip MD5 Hash = f0e2d3d17ff4abeb419d219e2fcfcb97
v3.10.257
Released: 07-05-2023
Free Mode:
General
New dialog displayed when write-overlay differencing file is running out of memory or disk space
New dialog displayed when “AD encryption” is encountered
Bug fixes related to write-original mounting resulting in read-only behavior and final 64kb being read only in write-temporary mode
Error message no longer displayed when removing both a Storage Spaces drive and its underlying drives at the same time
Fixed DiscUtils bug that would result in unexpected characters within NTFS $UpCase metafile when creating a new image
Differential file selection dialog now remembers previous differential file location and only displays files with .diff extension
Updated GUI and CLI readmes
BitLocker
Professional Mode:
Launch VM
New PIN brute force feature (up to six digit numeric), particularly useful when an immediate DPAPI bypass is unavailable
New nested virtualization and extreme isolation options via new Advanced menu options
Improved support for DPAPI bypass against Azure AD accounts
Adjustments to scanning for dirty file systems to make launching VMs more reliable
Improved handling of disabled or otherwise invalid Active Directory accounts and disabled local accounts
Logons involving certain Active Directory scenarios no longer require a reboot
Improved handling of corrupt Registry hives and transaction logs
New dialog displayed when open files are found on volumes about to be launched into VMs
Adjustments to make launching newer builds of Windows 11 into VMs more reliable
Locked BitLocker volumes are now dealt with earlier in the Launch VM workflow
Adjusted behavior of not selecting Windows authentication bypass against Microsoft cloud accounts
The "Launch VM" button becomes "Reconnect VM" after VMs are launched in case consoles are unexpectedly disconnected
Added warnings related to problematic Hyper-V installations
Fixed problem with frozen disk I/O which would sometimes occur when preparing to launch VMs
WinDbg support extended to WinDbg from Microsoft Apps
Improved workflow when DPAPI bypass against multiple accounts is available
Warning displayed when differential file is being stored in RAM but less than 16GB of free physical memory is found
Mount VSCs
Mount archive
Arsenal-Image-Mounter-v3.10.257.zip MD5 Hash = a1d97d423d34ed69ab34e6d90b30376e
v3.9.239
Released: 02-28-2023
Free Mode:
General
Increased privileges required to open virtual dd files to limit possible abuse of the virtual dd functionality
Fixed issues with large numbers of E01 segments which could result in an I/O error, TRIM commands being disabled against sparsely-allocated dd images and dynamically-allocated RAM disks, and dialogs related to missing or incompatible hypervisors
AIM CLI now includes a “—writable” switch and mounts read-only by default
Updated GUI and CLI readmes
Arsenal-Image-Mounter-v3.9.239.zip MD5 Hash = f6234004d84696002e6b62e82a1bf8b0
v3.9.235
Released: 01-20-2023
Free Mode:
Virtual dd: Partitions are now exposed in addition to disks, volumes, and VSCs. This may be useful when inspecting partitions that do not get assigned driver letters and/or contain file systems unrecognized by Windows.
General: Fixed issue with error displayed after AIM driver install (even though driver was installed successfully), updated GUI readme
Professional Mode:
Launch VM: Additional AV evasion within the virtual machines launched by AIM
Windows file system driver bypass: Fixed partition table validation which was too strict, fixed issue with errors related to file systems in one partition impacting recognition of other partitions, and fixed inability to open small files with all-zero content (without any physical cluster allocation) in ext file systems
Mount archive: Fixed issue with tar header validation being too strict, preventing proper mounting when owner/group names were missing
Arsenal-Image-Mounter_v3.9.235.zip MD5 Hash = 2509558fcea81d606e820b0e1f255f90
v3.9.218
Released: 07-28-2022
Free Mode:
Virtual dd: Upon enabling the virtual dd function, all available disks, volumes, and VSCs (whether AIM-mounted/attached or not) will be virtually exposed in a new volume as read-only raw disk images with the “.dd” extension. Disks will be exposed by their “PhysicalDrive” number, volumes will be exposed both by their currently assigned Windows drive letter and GUID, and VSCs by their volume GUID and timestamp.
Physical disks: Mounted disk images can now be written to physical disks with optional free space clearing (TRIM command for TRIM-enabled SSD disks, otherwise traditional clearing)
GUI: Mount points in AIM’s main screen are now displayed in collapsed details
Disk Image Mounting: Support for qcow/qcow2 format
Disk Image Mounting: Disk images which contain only an ISO9660 file system (CD-ROM) are now automatically mounted as virtual CD/DVDs
Updated readmes
Professional Mode:
VM Launching: DPAPI Bypass scenarios have been significantly expanded, including from VSCs AIM has launched into VMs as well as scenarios pre-Windows 10
VM Launching: In some DPAPI-bypass scenarios involving PIN (or non-password) authentication solely (i.e. password authentication was not an additional option), revealing browser-stored credentials could be problematic. AIM now actively resolves this problem.
VM Launching: In some DPAPI-bypass scenarios, for example involving Windows 8 or 8.1 and Microsoft online accounts, automatic logon does not work which makes AIM’s DPAPI bypass less intuitive. To solve this, AIM VM Tools now displays passwords in clear text so that AIM users can use them for logon with DPAPI fully unlocked.
VM Launching: New Linux authentication bypass
VM Launching: Additional boot driver assistance which results (for example) in more successful VM launches directly from VSCs
VM Launching: The Launch VM option “Boot with last Windows shutdown time” now displays the last shutdown time
VM Launching: VMs are now created with up to 6 GB RAM if >10 GB is available (previously max 4 GB) and with number of CPU cores set to half the number of physical host CPU cores (previously always 2 CPU cores)
VSC Mounting: VSC timestamps are more clearly identified in AIM’s main window and folders containing mounted VSCs
VSC Mounting: Enhanced performance mounting and accessing VSCs
Windows File System Driver Bypass: Support for single disk, non-striped, lvm/lvm2 volumes
Windows File System Driver Bypass: Fixed bugs in DiscUtils NTFS implementation which prevented mounting of some disk images, additional bug fixes in other DiscUtils file system implementations, many optimizations related to both DiscUtils and Dokan 2 resulting in significant performance improvements
Note: To enable Arsenal Image Mounter’s full functionality, the latest .NET 6 is now required.