Skip to content

Read FTK Imager AD-encrypted images with their password - #344

Merged
abrignoni merged 1 commit into
mainfrom
feat/adcrypt
Sep 27, 2026
Merged

abrignoni merged 1 commit into
mainfrom
feat/adcrypt

Conversation

@abrignoni

Copy link
Copy Markdown
Owner

Adds FTK Imager's AD encryption to raw image input (-t raw).

  • E01, SMART and raw (dd) sets opened with their password; a raw set from any of its numbered files
  • Same password options and GUI dialog as encrypted Apple disk images
  • Vendored qnxprobe 1.42 and ewfprobe 0.6.0 (which also fixes two .dmg layout cases)

FTK Imager's encrypted E01 and two-file raw set of a public NTFS image give the same tables as the plain E01.

🤖 Generated with Claude Code

Raw image input (-t raw) now opens an E01, SMART or raw (dd) set FTK
Imager encrypted with AD encryption, with the password taken the same way
as for an encrypted Apple disk image: --image_password_file or
--image_password_env, a terminal prompt, or the GUI's masked dialog. A raw
set opens from any of its numbered files, and the run log names it as the
reader reports it rather than as a split image.

Vendors qnxprobe 1.42 (db03a94) and ewfprobe 0.6.0 (01731cc). ewfprobe
0.6.0 also reads a .dmg whose data fork does not start its file, and one
whose declared XML length runs past </plist>.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@abrignoni
abrignoni merged commit 750b11f into main Sep 27, 2026
9 checks passed
@abrignoni
abrignoni deleted the feat/adcrypt branch September 27, 2026 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant