<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>DFIR蘇小沐</title><link>https://dfirdd.com</link><atom:link href="https://dfirdd.com/rss.xml" rel="self" type="application/rss+xml"/><description>蘇小沐电子取证</description><generator>Halo v2.23.2</generator><language>zh-cn</language><image><url>https://dfirdd.com/upload/%E5%B0%81%E9%9D%A2%20DFIR.jpg</url><title>DFIR蘇小沐</title><link>https://dfirdd.com</link></image><lastBuildDate>Tue, 7 Apr 2026 12:52:06 GMT</lastBuildDate><item><title><![CDATA[【Mac取证篇】macOS取证注意事项]]></title><link>https://dfirdd.com/SXM/MacOS-Forensics/macqu-zheng-pian-macosqu-zheng-zhu-yi-shi-xiang</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90Mac%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91macOS%E5%8F%96%E8%AF%81%E6%B3%A8%E6%84%8F%E4%BA%8B%E9%A1%B9&amp;url=/SXM/MacOS-Forensics/macqu-zheng-pian-macosqu-zheng-zhu-yi-shi-xiang" width="1" height="1" alt="" style="opacity:0;">今天看到群组小伙伴讨论这个，就想起来了多年前做的笔记，找了下没找到，已经不懂现在躺在那块硬盘里吃灰，算了，让它继续躺着吧，最近事情有点多，公众号都没时间更新……。本篇直接使用的Apple官方文档，针对"Mac文件保险箱"和"Mac时间机器"，以及自行外延了一点小知识做个小结科普，感兴趣的可以自行去A]]></description><guid isPermaLink="false">/SXM/MacOS-Forensics/macqu-zheng-pian-macosqu-zheng-zhu-yi-shi-xiang</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FMa%25E5%258F%2596%25E8%25AF%2581%25E6%25B3%25A8%25E6%2584%258F%25E4%25BA%258B%25E9%25A1%25B901.png&amp;size=m" type="image/jpeg" length="98953"/><category>MacOS取证</category><pubDate>Sat, 28 Mar 2026 02:53:37 GMT</pubDate></item><item><title><![CDATA[【镜像仿真篇】DD、E01系统镜像仿真教程]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-dd-e01xi-tong-jing-xiang-fang-zhen-jiao-cheng</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91DD%E3%80%81E01%E7%B3%BB%E7%BB%9F%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E6%95%99%E7%A8%8B&amp;url=/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-dd-e01xi-tong-jing-xiang-fang-zhen-jiao-cheng" width="1" height="1" alt="" style="opacity:0;">【镜像仿真篇】DD、E01系统镜像仿真教程 理想滚烫，人生再无星河！ 在电子取证分析过程中，我们经常遇到DD、E01等系统镜像，然而，并非所有工作者手边都有自动化取证软件。我们如何利用手上的资源，将镜像给仿真起来查看里面的数据？本文以E01镜像为例（DD镜像相同），我们来通过简单的操作进行手动仿真，]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-dd-e01xi-tong-jing-xiang-fang-zhen-jiao-cheng</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F-DD%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="120461"/><category>镜像仿真</category><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:51 GMT</pubDate></item><item><title><![CDATA[【镜像仿真篇】Linux镜像仿真、E01镜像取证]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-linuxjing-xiang-fang-zhen-e01jing-xiang-qu-zheng</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91Linux%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E3%80%81E01%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81&amp;url=/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-linuxjing-xiang-fang-zhen-e01jing-xiang-qu-zheng" width="1" height="1" alt="" style="opacity:0;">【镜像仿真篇】Linux镜像仿真、E01镜像取证 主要是Linux镜像仿真（DD、E01仿真相同），还介绍了特别特殊的一个情况，就是在虚拟磁盘里的镜像再挂载本地，出现的“磁盘占用”，导致无法成功仿真的问题！—【蘇小沐】 前篇"]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-linuxjing-xiang-fang-zhen-e01jing-xiang-qu-zheng</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F-Linux%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="108684"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:51 GMT</pubDate></item><item><title><![CDATA[【电子取证：镜像仿真篇】DD、E01系统镜像动态仿真]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/dian-zi-qu-zheng-jing-xiang-fang-zhen-pian-dd-e01xi-tong-jing-xiang-dong-tai-fang-zhen</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E7%94%B5%E5%AD%90%E5%8F%96%E8%AF%81%EF%BC%9A%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91DD%E3%80%81E01%E7%B3%BB%E7%BB%9F%E9%95%9C%E5%83%8F%E5%8A%A8%E6%80%81%E4%BB%BF%E7%9C%9F&amp;url=/SXM/Windows-Forensics/dian-zi-qu-zheng-jing-xiang-fang-zhen-pian-dd-e01xi-tong-jing-xiang-dong-tai-fang-zhen" width="1" height="1" alt="" style="opacity:0;">在电子取证分析过程中，我们经常遇到DD、E01等系统镜像，然而，并非所有工作者手边都有自动化取证软件，我们如何利用手上的资源，将镜像给仿真起来查看里面的数据？ 本文以E01镜像为例（DD镜像相同），我们来通过简单的操作进行手动仿真，让镜像数据活起来！ 一、DD、E01系统镜像动态仿真 星河滚烫，人生]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/dian-zi-qu-zheng-jing-xiang-fang-zhen-pian-dd-e01xi-tong-jing-xiang-dong-tai-fang-zhen</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F-DD%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="120461"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:51 GMT</pubDate></item><item><title><![CDATA[【镜像仿真篇】Arsenal Image Mounter镜像挂载利器]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-arsenal-image-mounterjing-xiang-gua-zai-li-qi</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91Arsenal%20Image%20Mounter%E9%95%9C%E5%83%8F%E6%8C%82%E8%BD%BD%E5%88%A9%E5%99%A8&amp;url=/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-arsenal-image-mounterjing-xiang-gua-zai-li-qi" width="1" height="1" alt="" style="opacity:0;">【镜像仿真篇】Arsenal Image Mounter镜像挂载利器 Arsenal Image Mounter是一款非常优秀的磁盘挂载工具，在Microsoft Windows中可以将磁盘映像的内容作为“真实磁盘”挂载到系统中—【蘇小沐】 1、Arsenal Image Mounter简介 Ars]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-arsenal-image-mounterjing-xiang-gua-zai-li-qi</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FArsenal%2520Image%2520Mounter-%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="103534"/><category>镜像仿真</category><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:51 GMT</pubDate></item><item><title><![CDATA[【镜像仿真篇】ESXi镜像仿真教程]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-esxijing-xiang-fang-zhen-jiao-cheng</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91ESXi%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E6%95%99%E7%A8%8B&amp;url=/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-esxijing-xiang-fang-zhen-jiao-cheng" width="1" height="1" alt="" style="opacity:0;">【镜像仿真篇】ESXi镜像仿真教程 我以为不会再有使用FTK Imager低版本的时候，毕竟Arsenal Image Mounte是我目前遇到的最强镜像挂载软件，直到这次遇到了这个ESXi镜像仿真的时候一直报错-–【蘇小沐】 1、实验环境]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-esxijing-xiang-fang-zhen-jiao-cheng</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F-ESXi%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="62924"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:51 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】DD和E01镜像格式区别（简）]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ddhe-e01jing-xiang-ge-shi-qu-bie-jian</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91DD%E5%92%8CE01%E9%95%9C%E5%83%8F%E6%A0%BC%E5%BC%8F%E5%8C%BA%E5%88%AB%EF%BC%88%E7%AE%80%EF%BC%89&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ddhe-e01jing-xiang-ge-shi-qu-bie-jian" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】DD和E01镜像格式区别（简） 简单总结下—【蘇小沐】 1、实验环境]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ddhe-e01jing-xiang-ge-shi-qu-bie-jian</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=https%3A%2F%2Fimage.baidu.com%2Fsearch%2Fdown%3Furl%3Dhttps%3A%2F%2Ftvax3.sinaimg.cn%2F%2Flarge%2F0072Vf1pgy1foxki3cf3xj31hc0u0wt7.jpg&amp;size=m" type="image/jpeg" length="0"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:50 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】GHO系统镜像仿真还原教程]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ghoxi-tong-jing-xiang-fang-zhen-huan-yuan-jiao-cheng</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91GHO%E7%B3%BB%E7%BB%9F%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E8%BF%98%E5%8E%9F%E6%95%99%E7%A8%8B&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ghoxi-tong-jing-xiang-fang-zhen-huan-yuan-jiao-cheng" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】GHO系统镜像仿真还原教程 简要记录下GHO系统镜像还原及系统仿真的过程—【蘇小沐】 1、实验环境]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ghoxi-tong-jing-xiang-fang-zhen-huan-yuan-jiao-cheng</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FGHO%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B0%2581%25E9%259D%25A2.jpeg&amp;size=m" type="image/jpeg" length="29850"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:50 GMT</pubDate></item><item><title><![CDATA[【镜像仿真篇】磁盘镜像仿真常见错误]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-ci-pan-jing-xiang-fang-zhen-chang-jian-cuo-wu</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91%E7%A3%81%E7%9B%98%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E5%B8%B8%E8%A7%81%E9%94%99%E8%AF%AF&amp;url=/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-ci-pan-jing-xiang-fang-zhen-chang-jian-cuo-wu" width="1" height="1" alt="" style="opacity:0;">【镜像仿真篇】磁盘镜像仿真常见错误 记系统镜像仿真常见错误集-–【蘇小沐】 1、实验环境]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-fang-zhen-pian-ci-pan-jing-xiang-fang-zhen-chang-jian-cuo-wu</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E8%2599%259A%25E6%258B%259F%25E6%259C%25BA%25E7%25A3%2581%25E7%259B%2598%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B8%25B8%25E8%25A7%2581%25E9%2594%2599%25E8%25AF%25AF%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="120553"/><category>镜像仿真</category><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:50 GMT</pubDate></item><item><title><![CDATA[【镜像仿真篇】WindowsServer服务器镜像仿真]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/44c65afa-4575-4603-9c24-ad13129acb4c</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E7%AF%87%E3%80%91WindowsServer%E6%9C%8D%E5%8A%A1%E5%99%A8%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F&amp;url=/SXM/Windows-Forensics/44c65afa-4575-4603-9c24-ad13129acb4c" width="1" height="1" alt="" style="opacity:0;">## 【镜像仿真篇】WindowsServer服务器镜像仿真 介绍镜像转换、vmdk镜像仿真注意的一些事项---【蘇小沐】 （一）qemu-img镜像转换工具 ---------------- qemu-img(v2.3.0.0)镜像转换工具，对应有Windows和Linx版本，通过"命令"将raw]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/44c65afa-4575-4603-9c24-ad13129acb4c</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=https%3A%2F%2Fimage.baidu.com%2Fsearch%2Fdown%3Furl%3Dhttps%3A%2F%2Ftvax3.sinaimg.cn%2F%2Flarge%2F0072Vf1pgy1fodqoysytvj31hc0u0qcq.jpg&amp;size=m" type="image/jpeg" length="0"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:49 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】DD系统镜像仿真问题的一些补充说明]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ddxi-tong-jing-xiang-fang-zhen-wen-ti-de-yi-xie-bu-chong-shuo-ming</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91DD%E7%B3%BB%E7%BB%9F%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E9%97%AE%E9%A2%98%E7%9A%84%E4%B8%80%E4%BA%9B%E8%A1%A5%E5%85%85%E8%AF%B4%E6%98%8E&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ddxi-tong-jing-xiang-fang-zhen-wen-ti-de-yi-xie-bu-chong-shuo-ming" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】DD系统镜像仿真问题的一些补充说明 系统千千万，环境占一半，遇到问题建议多重新挂载镜像，多尝试，站在岸上永远学不会游泳—【蘇小沐】 实验环境 Windows建议用专业版，功能全。]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ddxi-tong-jing-xiang-fang-zhen-wen-ti-de-yi-xie-bu-chong-shuo-ming</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F-DD%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="120461"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:49 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】仿真碎片-记一次镜像仿真失败的复盘过程]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-fang-zhen-sui-pian-ji-yi-ci-jing-xiang-fang-zhen-shi-bai-de-fu-pan-guo-cheng</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91%E4%BB%BF%E7%9C%9F%E7%A2%8E%E7%89%87-%E8%AE%B0%E4%B8%80%E6%AC%A1%E9%95%9C%E5%83%8F%E4%BB%BF%E7%9C%9F%E5%A4%B1%E8%B4%A5%E7%9A%84%E5%A4%8D%E7%9B%98%E8%BF%87%E7%A8%8B&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-fang-zhen-sui-pian-ji-yi-ci-jing-xiang-fang-zhen-shi-bai-de-fu-pan-guo-cheng" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】仿真碎片-记一次镜像仿真失败的复盘过程 这个是很久以前的一个镜像实验，当时仿真可以看到Windows的启动界面，但却一直无法正常进入系统，不断的尝试修复，都是显示错误，最后把类型改为IDE后，成功仿真进入系统—【蘇小沐】 1、无法仿真成功]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-fang-zhen-sui-pian-ji-yi-ci-jing-xiang-fang-zhen-shi-bai-de-fu-pan-guo-cheng</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F-%25E9%2595%259C%25E5%2583%258F%25E4%25BB%25BF%25E7%259C%259F%25E5%25A4%25B1%25E8%25B4%25A5%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="123511"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:48 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】VMware虚拟机配置文件取证]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-vmwarexu-ni-ji-pei-zhi-wen-jian-qu-zheng</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91VMware%E8%99%9A%E6%8B%9F%E6%9C%BA%E9%85%8D%E7%BD%AE%E6%96%87%E4%BB%B6%E5%8F%96%E8%AF%81&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-vmwarexu-ni-ji-pei-zhi-wen-jian-qu-zheng" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】VMware虚拟机配置文件取证 虚拟机取证中，通常主要关注.log、.vmdk、.vmem三个文件，里面包含虚拟机的大部分资料信息—【蘇小沐】 1、测试环境]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-vmwarexu-ni-ji-pei-zhi-wen-jian-qu-zheng</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E5%258F%2596%25E8%25AF%2581%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="108059"/><category>镜像仿真</category><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:48 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】听说你还分不清镜像的源盘哈希和镜像文件的哈希？]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ting-shuo-ni-huan-fen-bu-qing-jing-xiang-de-yuan-pan-ha-xi-he-jing-xiang-wen-jian-de-ha-xi</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91%E5%90%AC%E8%AF%B4%E4%BD%A0%E8%BF%98%E5%88%86%E4%B8%8D%E6%B8%85%E9%95%9C%E5%83%8F%E7%9A%84%E6%BA%90%E7%9B%98%E5%93%88%E5%B8%8C%E5%92%8C%E9%95%9C%E5%83%8F%E6%96%87%E4%BB%B6%E7%9A%84%E5%93%88%E5%B8%8C%EF%BC%9F&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ting-shuo-ni-huan-fen-bu-qing-jing-xiang-de-yuan-pan-ha-xi-he-jing-xiang-wen-jian-de-ha-xi" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】听说你还分不清镜像的源盘哈希和镜像文件的哈希？ 听说你还分不清镜像的源盘哈希和镜像文件的哈希？镜像的两层防护，镜像的源盘哈希、镜像文件的哈希傻傻分不清—【蘇小沐】 1、实验环境]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-ting-shuo-ni-huan-fen-bu-qing-jing-xiang-de-yuan-pan-ha-xi-he-jing-xiang-wen-jian-de-ha-xi</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2FFTK%2520Imager%25E9%2595%259C%25E5%2583%258F%25E7%259A%2584%25E6%25BA%2590%25E7%259B%2598%25E5%2593%2588%25E5%25B8%258C%25E5%25B0%2581%25E9%259D%25A2.jpeg&amp;size=m" type="image/jpeg" length="37058"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:48 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】常见镜像文件类型]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-chang-jian-jing-xiang-wen-jian-lei-xing</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91%E5%B8%B8%E8%A7%81%E9%95%9C%E5%83%8F%E6%96%87%E4%BB%B6%E7%B1%BB%E5%9E%8B&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-chang-jian-jing-xiang-wen-jian-lei-xing" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】常见镜像文件类型 人生若都如镜像—【蘇小沐】 常见镜像文件类型]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-chang-jian-jing-xiang-wen-jian-lei-xing</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E6%2596%2587%25E4%25BB%25B6%25E7%25B1%25BB%25E5%259E%258B-%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="115181"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:48 GMT</pubDate></item><item><title><![CDATA[【镜像取证篇】qemu-img磁盘镜像转换神器]]></title><link>https://dfirdd.com/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-qemu-imgci-pan-jing-xiang-zhuan-huan-shen-qi</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E9%95%9C%E5%83%8F%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91qemu-img%E7%A3%81%E7%9B%98%E9%95%9C%E5%83%8F%E8%BD%AC%E6%8D%A2%E7%A5%9E%E5%99%A8&amp;url=/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-qemu-imgci-pan-jing-xiang-zhuan-huan-shen-qi" width="1" height="1" alt="" style="opacity:0;">【镜像取证篇】qemu-img磁盘镜像转换神器 转换磁盘镜像格式，便于仿真搭建–【蘇小沐】 （一）qemu-img：磁盘镜像格式转换工具 1、功能简介 qemu-]]></description><guid isPermaLink="false">/SXM/Windows-Forensics/jing-xiang-qu-zheng-pian-qemu-imgci-pan-jing-xiang-zhuan-huan-shen-qi</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F%25E9%2595%259C%25E5%2583%258F%25E8%25BD%25AC%25E6%258D%25A2-QEMU%25E9%2595%259C%25E5%2583%258F%25E8%25BD%25AC%25E6%258D%25A2%25E8%25BD%25AF%25E4%25BB%25B6%25E5%25B0%2581%25E9%259D%25A2.png&amp;size=m" type="image/jpeg" length="121011"/><category>Windows取证</category><pubDate>Sat, 28 Mar 2026 02:51:47 GMT</pubDate></item><item><title><![CDATA[【加解密篇】Passware Kit Forensic暴力美学-已知部分密码自定义解密详细参数设置]]></title><link>https://dfirdd.com/SXM/Cyber-Forensics/jia-jie-mi-pian-passware-kit-forensicbao-li-mei-xue-yi-zhi-bu-fen-mi-ma-zi-ding-yi-jie-mi-xiang-xi-can-shu-she-zhi</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E5%8A%A0%E8%A7%A3%E5%AF%86%E7%AF%87%E3%80%91Passware%20Kit%20Forensic%E6%9A%B4%E5%8A%9B%E7%BE%8E%E5%AD%A6-%E5%B7%B2%E7%9F%A5%E9%83%A8%E5%88%86%E5%AF%86%E7%A0%81%E8%87%AA%E5%AE%9A%E4%B9%89%E8%A7%A3%E5%AF%86%E8%AF%A6%E7%BB%86%E5%8F%82%E6%95%B0%E8%AE%BE%E7%BD%AE&amp;url=/SXM/Cyber-Forensics/jia-jie-mi-pian-passware-kit-forensicbao-li-mei-xue-yi-zhi-bu-fen-mi-ma-zi-ding-yi-jie-mi-xiang-xi-can-shu-she-zhi" width="1" height="1" alt="" style="opacity:0;">【加解密篇】Passware Kit Forensic暴力美学-已知部分密码自定义解密详细参数设置 都说"自制武器不一定是最强的，但最强的武器一定是自制的"，对于取证工具也是一样，虽然默认配置足够强，但如果我们能根据实时情景自定义参数配置，那么往往能事半功倍—【蘇小沐】]]></description><guid isPermaLink="false">/SXM/Cyber-Forensics/jia-jie-mi-pian-passware-kit-forensicbao-li-mei-xue-yi-zhi-bu-fen-mi-ma-zi-ding-yi-jie-mi-xiang-xi-can-shu-she-zhi</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2F20240501_074044.png&amp;size=m" type="image/jpeg" length="72014"/><category>加解密取证</category><pubDate>Sat, 28 Mar 2026 02:29:44 GMT</pubDate></item><item><title><![CDATA[【加解密篇】Passware Encryption Analyzer快速检测加密文件软件]]></title><link>https://dfirdd.com/SXM/jia-jie-mi-qu-zheng/707f6902-1ee5-45af-9920-41fd8a67d97d</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E5%8A%A0%E8%A7%A3%E5%AF%86%E7%AF%87%E3%80%91Passware%20Encryption%20Analyzer%E5%BF%AB%E9%80%9F%E6%A3%80%E6%B5%8B%E5%8A%A0%E5%AF%86%E6%96%87%E4%BB%B6%E8%BD%AF%E4%BB%B6&amp;url=/SXM/jia-jie-mi-qu-zheng/707f6902-1ee5-45af-9920-41fd8a67d97d" width="1" height="1" alt="" style="opacity:0;">## 【加解密篇】Passware Encryption Analyzer快速检测加密文件软件 密码加密分析仪是一种免费工具，可扫描系统以检测受保护或加密的文件、存档和其他加密类型的文件---【蘇小沐】 ## （一）扫描对象 可全盘扫描或者自定义扫描驱动或文件夹等，并计算Hash值。 !\[Imag]]></description><guid isPermaLink="false">/SXM/jia-jie-mi-qu-zheng/707f6902-1ee5-45af-9920-41fd8a67d97d</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=https%3A%2F%2Fimage.baidu.com%2Fsearch%2Fdown%3Furl%3Dhttps%3A%2F%2Ftvax3.sinaimg.cn%2F%2Flarge%2F0072Vf1pgy1fodqpbkx8xj30xc0nke81.jpg&amp;size=m" type="image/jpeg" length="0"/><category>加解密取证</category><pubDate>Sat, 28 Mar 2026 02:29:44 GMT</pubDate></item><item><title><![CDATA[【加解密篇】Passware Kit Forensic自定义解密类型教程]]></title><link>https://dfirdd.com/SXM/jia-jie-mi-qu-zheng/bb21490b-44d0-4048-8893-6d91087ec666</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E5%8A%A0%E8%A7%A3%E5%AF%86%E7%AF%87%E3%80%91Passware%20Kit%20Forensic%E8%87%AA%E5%AE%9A%E4%B9%89%E8%A7%A3%E5%AF%86%E7%B1%BB%E5%9E%8B%E6%95%99%E7%A8%8B&amp;url=/SXM/jia-jie-mi-qu-zheng/bb21490b-44d0-4048-8893-6d91087ec666" width="1" height="1" alt="" style="opacity:0;">## 【加解密篇】Passware Kit Forensic自定义解密类型教程 都说"自制武器不一定是最强的，但最强的武器一定是自制的"，对于取证工具也是一样，虽然默认配置足够强，但如果我们能根据实时情景自定义参数配置，那么往往能事半功倍---【蘇小沐】 Passware Kit Forensic是]]></description><guid isPermaLink="false">/SXM/jia-jie-mi-qu-zheng/bb21490b-44d0-4048-8893-6d91087ec666</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=https%3A%2F%2Fimage.baidu.com%2Fsearch%2Fdown%3Furl%3Dhttps%3A%2F%2Ftvax3.sinaimg.cn%2F%2Flarge%2Fa15b4afely1fnt9j9eed7j21hc0u04c4.jpg&amp;size=m" type="image/jpeg" length="0"/><category>加解密取证</category><pubDate>Sat, 28 Mar 2026 02:29:22 GMT</pubDate></item><item><title><![CDATA[【电子取证篇】哈希校验值的变与不变]]></title><link>https://dfirdd.com/SXM/Cyber-Forensics/dian-zi-qu-zheng-pian-ha-xi-xiao-yan-zhi-de-bian-yu-bu-bian</link><description><![CDATA[<img src="https://dfirdd.com/plugins/feed/assets/telemetry.gif?title=%E3%80%90%E7%94%B5%E5%AD%90%E5%8F%96%E8%AF%81%E7%AF%87%E3%80%91%E5%93%88%E5%B8%8C%E6%A0%A1%E9%AA%8C%E5%80%BC%E7%9A%84%E5%8F%98%E4%B8%8E%E4%B8%8D%E5%8F%98&amp;url=/SXM/Cyber-Forensics/dian-zi-qu-zheng-pian-ha-xi-xiao-yan-zhi-de-bian-yu-bu-bian" width="1" height="1" alt="" style="opacity:0;">哈希值（散列值）是针对电子数据内容来计算的，内容变则哈希变；但计算对象的文件名、文件时间等属性改变不会影响散列值！！！-–【蘇小沐】 注意事项 文件名称改变：哈希值不会变 而同一份文件，只是被重命名了文件名称，那么哈希并不会改变！！！（说到这又得吐槽下微信转发文件的SB操作，每转发一次，自动复制一份]]></description><guid isPermaLink="false">/SXM/Cyber-Forensics/dian-zi-qu-zheng-pian-ha-xi-xiao-yan-zhi-de-bian-yu-bu-bian</guid><dc:creator>蘇小沐</dc:creator><enclosure url="https://dfirdd.com/apis/api.storage.halo.run/v1alpha1/thumbnails/-/via-uri?uri=%2Fupload%2Fimage_3.5a5eeb1f.png&amp;size=m" type="image/jpeg" length="82633"/><category>加解密取证</category><pubDate>Sat, 28 Mar 2026 02:29:22 GMT</pubDate></item></channel></rss>