-
Notifications
You must be signed in to change notification settings - Fork 343
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
log2timeline.py: unable to read backup NTFS volume header #3592
Comments
It looks like your images are missing the NTFS back-up volume header. Are these images of a volume created by a live imaging tool on Windows? Are you sure your imaging tool includes the full volume and not silently skips the last sector? Have a look at https:/libyal/libbfoverlay/wiki/Examples#correcting-truncated-windows-live-volume-images to see if that can help work-around the missing data |
Possibly related log2timeline/dfvfs#514 |
One was done with I'll try some of the recovery tips from your link later in the week. |
any other reasons why the backup volume header could be missing? |
Description of problem:
We have two images (from different aquisition tools, differents systems, different examiner) which fail to be parsed with log2timeline.py. Shortly after starting the process, the following error is given:
We tried different tools to convert the image files (from EWF to EWF, from EWF to RAW) and retry parsing without success. Both images open with XWays without trouble. Also tried
--no_vss
without success.Command line and arguments:
log2timeline.py --workers 1 --debug timeline.plaso /redactedt/62_redacted/redacted.E01
Source data:
Please provide the source data you used when you experienced the problem.
For publicly available data please provide an URL or path of the source data.
Plaso version:
Operating system Plaso is running on:
Installed using latest docker image
Installation method:
Installed using latest docker image
Debug output/tracebacks:
logfile just contains one line:
The text was updated successfully, but these errors were encountered: