I’m in your hypervisor, collecting your evidence
ID: 7b5c2b8e-4652-5a40-954b-9ca53cc2c80a
STIX ID: report--7b5c2b8e-4652-5a40-954b-9ca53cc2c80a
Feed Name: Fox-IT blog
Executive summary: This blog post describes Fox-IT's development of hypervisor data acquisition capabilities, detailing reverse engineering of VMware ESXi internals (VMFS, FAT16 bootbank, vmtar, Envelope encryption, filesystem mounting) and adding Hyper-V VMCX parsing into their Dissect/Acquire tooling to enable live and offline evidence collection from hypervisors; it notes limitations (local/iSCSI storage only) and emphasizes preservation, stealth, and scalability for DFIR workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
