


Windows file system driver bypass (FAT, NTFS, ExFAT, HFS+, Ext2/3/4, etc.)Įxposure of NTFS metadata, slack, and unallocated in Windows file system driver bypass mode Write mounted disk images to physical disks with optional free space clearing Launch virtual machines directly from Volume Shadow CopiesĪttach to actual physical disks (fixed and removable) to leverage virtual machine launching, VSC mounting, etc.

Volume Shadow Copy mounting (standard, with Windows NTFS driver bypass, or as complete disks) Professional Mode offers all Free Mode functionality plus:Įffortlessly launch virtual machines from disk imagesĮxtremely powerful Windows authentication and DPAPI bypasses within virtual machines MBR injection, fake disk signatures, removable disk emulation, and much more RAM disk creation with either static or dynamic memory allocation Identify (with details), unlock, fully decrypt, and disable/suspend BitLocker-protected volumesĪccess disks, volumes, and Volume Shadow Copies as virtual dd files

Save "physically" mounted objects to various disk image formats Temporary write support with replayable differencing files for all supported disk image formats Mount raw, forensic, and virtual machine disk images as complete (a/k/a “real”) disks on Windows
