Open MariasStory opened 3 years ago
Hi. Unfortunately this needs to be implemented at the sleuthkit level. See: https://github.com/sleuthkit/sleuthkit/issues/1148 https://github.com/sleuthkit/sleuthkit/issues/1191
As a workaround, you can create an AD1 volume per partition (may include unallocated) using FTKImager and IPED will process the AD1 directly without sleuthkit.
Hi @lfcnassif, you've done a good job in paying attention to this problem. It seems that relying on sleuthkit is somewhat problematic. The Sleuthkit development is not so agile, and the issues are not being addressed. I suggest automating some kind of workaround, not only for this case, but also for similar issues.
Work in progress in TSK here: https://github.com/sleuthkit/sleuthkit/pull/2751
Depends on #1340
Reopening, Sleuthkit-4.12.0 windows build is not linking to libvslvm automatically, we'll have to adjust their build...
Hi, Congratulations on the progress with the cool tool. I just Love it. Can you please improve the lvm/lvm2 volumes parsing? FTKimager is able to read it, but IPED does not recognize the separate volumes.