labgeek / VFAELinks

VMDK Forensic Artifact Extractor (VFAE) is windows based tool written in C++ that extracts files with a known location from VMDK images running the Windows operating system. The tool utilizes the VDDK (Virtual Disk Development Kit) API for the heavy lifting such as mounting, opening, and reading the VMDK selected. When vfae.exe is executed, i…
15Updated 10 years ago

Alternatives and similar repositories for VFAE

Users that are interested in VFAE are comparing it to the libraries listed below

Sorting: