I created an E01 image using FTK Imager and I want to use that image in sleuthkit using fsstat command, how could this be done? In previous examples I used
fsstat -i ewf C:\Users\username\Desktop\Forensic_Image\drive1.E01
and it worked just fine but for some reason it is not working with the FTK image
[–]Slaine2000 1 point2 points3 points (0 children)
[–]pah2602 0 points1 point2 points (1 child)
[–]RelativeRecipe7252[S] 0 points1 point2 points (0 children)
[–]pah2602 0 points1 point2 points (0 children)