vhd-forensic¶
Legacy VHD (Virtual PC / Virtual Server / Hyper-V Gen-1) forensic tooling in pure Rust, split the fleet way:
vhd-core— a read-only reader: opens Fixed and Dynamic VHDs and exposes the virtual sector stream asRead + Seek. Imports asvhd.vhd-forensic— an integrity analyzer: parses the footer raw (which the reader validates-and-discards) and reports tamper / structural anomalies asforensicnomicon::reportfindings.
// Analyze a VHD footer for integrity anomalies.
for anomaly in vhd_forensic::audit(&image_bytes) {
let finding = anomaly.to_finding(source); // forensicnomicon Finding
}
Trust but verify: panic-free (bounded readers, no unwrap in production, fuzzed),
and validated against real qemu-img images with an independent oracle — see
Validation.
Privacy Policy · Terms of Service · © 2026 Security Ronin Ltd