Many Windows®-based disk image mounting solutions mount the contents of disk images as shares or partitions, rather than complete (aka "physical or "real") disks, which limits their usefulness to digital forensics practitioners and others. Arsenal Image Mounter mounts the contents of disk images as complete disks in Windows, allowing users to benefit from disk-specific features like integration with Disk Manager, launching virtual machines (and then bypassing Windows authentication and DPAPI), managing BitLocker-protected volumes, mounting Volume Shadow Copies, and more.
"I recently used Arsenal Image Mounter in a complex fraud case to virtualize a forensic image from a Windows computer. Having the ability to bypass the Windows password made this a simple process and allowed me to demonstrate to my client how the Windows environment looked to the user at the time the forensic image was obtained. My client (an attorney) was very happy with this and I created visuals for use as exhibits. Later, we had cause to look at the Volume Shadow Copies (VSCs) to see how a particular document’s content changed over time. AIM allowed me to launch the VSCs into virtual machines, again bypassing passwords. My client was stunned that he could see how the document looked over time just as the user had seen it, and asked if this was voodoo forensics! Leveraging VSCs launched into virtual machines was crucial to this matter and was very jury friendly. In my long career in this field, I have seen only a few tools that have had such an impact on a case. AIM’s ability to launch VSCs into virtual machines along with Windows authentication bypass is the result of some amazing work that the talented people at Arsenal have done over the years. If you are involved in digital forensics, AIM should be in your toolkit."
David Greetham VP of Digital Forensics, Level Legal
It Just Works
"I used Arsenal Image Mounter’s virtual machine launching functionality to review some previous cases that had given me issues with one of our other tools. AIM’s Windows DPAPI bypass is impressive, and I was also impressed with the Linux login bypass. On a current investigation I appreciated AIM's ease of use – I just wanted a quick look at a forensic image and didn’t want to spend much time setting it up. I was able to immediately boot the forensic image and see what I needed in a matter of minutes. With our other tool, this would have required the tedious process of initial setup and multiple rounds of correcting errors to get a forensic image booted into a virtual machine. So I really like the “it just works” aspect of AIM.”
Buy an Arsenal license and choose a subscription length (see the increasing discounts!) that works best for you. Want to try AIM first? Download AIM now and use its free functionality, or email sales to evaluate Professional Mode.