cyberark / White-Phoenix

A tool to recover content from files encrypted with intermittent encryption
Apache License 2.0
214 stars 29 forks source link

Recover Virtual Machine Disk File #14

Open ureinhardt opened 3 months ago

ureinhardt commented 3 months ago

Is your feature request related to a problem? Please describe.

We were attacked by Quilin ransomeware that encrypted all our vm files in a VMware environment. We wanted to make use of White-Phoenix.py to try decrypt them. But apparently White-Phoenix.py is not capable of decrypting e.g. a vmdx virtual disk file itself but solely extract documents and file like jpg or pdf from it, if possible

Describe the solution you would like

It would be a huge benefit if White-Phoenix could bring back a whole vm virtual disk file.

Could this be possible?