Product Overview

Current Version: 4.5.9.853

Mount Image Pro

Mount Forensic Images

Mount Image Pro is a computer forensics tool for Computer Forensics investigations. It enables the mounting of:

  • EnCase .E01, .L01
  • AccessData FTK .E01, .AD1
  • Unix/Linux DD and RAW images
  • Forensic File Format .AFF
  • SMART
  • ISO (CD and DVD images)
  • VMWare
  • ProDiscover
  • Microsoft VHD
  • Apple DMG

image files as a drive letter under the Windows file system.

Try before you buy

Download Mount Image Pro and run it free for 14 days to full evaluate the software.

Key Features

  • Map images as a single drive letter to explore "Unused/Non partitioned" disk space or map specific drive letters to any or all partitions within the image files.
  • Use third party tools such as Recover My Files without the need to restore images to another PC. Now you can develop or use your own tools without the limitations a scripting language.
  • You do not need to have EnCase installed nor do your require an EnCase dongle to use Mount Image Pro. This gives you and your clients total flexibility when dealing with EnCase evidence files.

Maintain Forensic Integrity

It fully maintains the MD5 HASH integrity which can be tested by a reacquisition of the mounted drive and a comparison of MD5 checksums. It also will open EnCase password protected image files without the password.

Who is using Mount Image Pro:

Our key clients include:

  • FBI
  • USA Military Investigations
  • Corporate Investigations
  • Major Law Firms
  • State and Federal law enforcement agencies

System Requirements

  • Operating System: Windows NT/2000/XP/2003/Vista/7
  • RAM: 128 MB recommended
  • Hard Disk: At least 6 MB of free disk space

Immediate Product Activation

When you order Mount Image Pro you immediately receive a product activation key so that you can immediately Mount forensic images.

Features

 Mount EnCaseĀ® images (all versions)

 Mount RAW DD images

 Mount SMART images

 Mount as Physical or Logical

 READ ONLY access

 MD5 image HASH integrity

 Right Click image mounting Command line options

 Mount NTFS, FAT, FAT 16, FAT 32

 Compatible with 3rd party file systems Drivers for Linux

 Map images to drive letter on startup

 Open password protected images


MIPv4 - Mount using "Filesystem" optionMIPv4 - Mount using "Filesystem" optionMIPv4 - Mount Macintosh image filesMIPv4 - Mount Macintosh image filesMIPv4 - Mount and boot with MIP and VFCMIPv4 - Mount and boot with MIP and VFCMIPv4   Mount Windows 7 RAIDMIPv4 Mount Windows 7 RAIDMIPv4 Mount Hardware Raid 5MIPv4 Mount Hardware Raid 5

Whats new in MIP v4:

 mip

QuickStart Guide

 

Introducing Mount Image Pro v4

Mount Image Pro is a program that will 'mount' EnCase, FTK, DD, RAW, SMART, SafeBack, ISO, and VMWare image files as a drive letter (or physical drive) on your computer.

What does this 'mount as a drive letter' mean?

Mount Image Pro turns an image file of a computer (or a logical image file) into a drive letter on your computer system. This means that you can:

  • Browse the computer files like you do your own files with programs such as Windows Explorer;
  • Run third party applications, such as virus scanners, spyware scanners over your evidence files;
  • Run programs on the physical drive, such as GetData's Recover My Files; and,

you can do all this in a ready only "forensically secure" environment, as the contents of the image file will not be changed.

IMPORTANT: When dealing with forensic evidence files ensure that you have a verified and secured a master copy.

Mount Image Pro v3 System Requirements

Mount Image Pro will run on Windows NT4, 2000, XP, 2003, Vista and 7.

Installing Mount Image Pro v4

It is important that you UNINSTAL PREVIOUS VERSIONS of Mount Image Pro.

New Download Mount Image Pro v4

Current Version: 4.5.9.853

  1. The download is fully functional as a trial version for 14 days.
  2. Important: Uninstall any previous versions of Mount Image Pro.
  3. Download and install the program. Once installed, run Mount Image Pro from the desktop icon to mount .E01, .L01, .AD1, .RAW, .DD, .001, and other image formats.

14 Day Trial Version

Mount Image Pro v3 is distributed as trial software. After installation Mount Image Pro v3 will run without limitations for 14 days. At the end of the trial period of 14 days you must purchase a license key and enter this key into Mount Image Pro to continue to use the software. An option is also available to purchase an activation dongle with your license.

To Purchase a License

To purchase a license key click on the "purchase" links on this web site. Purchase is made via our secure server.

Your registration key will be displayed to you at the end of the purchase process and will also be sent to you by email (receipt of purchase is also provided). Activation dongles are sent by courier and take 3-8 days to arrive (depending on your location and customs procedures).

Please note that if your credit card cannot be immediately verified then your registration key will be sent by email only, and only once the verification has taken place.


To Mount Images from the Desktop

Open Mount Image Pro v4 from the desktop icon. Click the "Mount" button on the main program screen to open the selection window. To add to the selection window, click:

"Add Image" to add a forensic image file (E01, L01, AD1, RAW etc.)

"Add RAID" button to add a raid (learn more here).

"Network" to mount a remote drive via TCPIP (learn more here).

Select the device or image that you wish to mount and the press the "Mount Disk" or "Mount Filesystem" button:

Mount Image v4


The device or image will then mount and display in the main program screen:

Mount Image v4


If the drive is mounted with a drive letter, you should then be able to browse to the drive using Windows. Double click on the drive letter to open Windows Explorer.

 

Running Mount Image Pro v3 from the Command Line (DOS)

Open a DOS Window. Commands are issued on the command line using the syntax:

"MIP3.EXE Command [Options]".

(Note: in MIP v2 the command is "MIP.EXE Command [Options]").

All commands and options are case insensitive. The commands for MIP v3 are as follows:

STATUS Print MIP status information.
MOUNT Mount disk image file(s) as a virtual drive.
UNMOUNT Unmount disk image file(s).
VIEW Display information about a disk image file(s).
LOOKUP Lookup mounted drive letters or image files.
HELP Print command help.

The sample dos commands below will mount the evidence file "Evidence_File_1.e01" as drive S:

cd: C:\Program Files\Mount Image Pro 
MIP3 MOUNT C:\Evidence_File_1.e01 /L:S

For more details please check the Mount Image v3 help file.


Practical uses for Mount Image Pro

There are many practical applications for Mount Image Pro. For example

  • Providing Image Files to 3rd Parties

    Mount Image Pro does not require a EnCase to be installed or present when mounting an EnCase image. Police departments, government departments, lawyers, accountancy firms and bankruptcy firms are using Mount Image Pro to share forensic images with relevant parties in a cost effect and secure manner.

  • Data Recovery

    Although EnCase is regarded as one of the front line computer forensics tools, a user must rely on complex e-scripts to "carve" data from unallocated space. After mounting an EnCase image with Mount Image Pro, a user can run data recovery software such as Recover My Files to extract deleted files from the image. Using Recover My Files on mounted images is the equivalent to running over 300 different EnScripts!

  • Text Keyword Search

    Once an image has been mounted a keyword search tool, such as Google Desktop, Yahoo Search or X1 can be run over the mounted image to index all files in the image. The contents of the image can then easily be text searched by a third party, such as a lawyer or prosecutor.

  • Virus or Trojan Scan

    Often a defence raised to an allegation about computer misuse is that the system was infected by a virus or a trojan which was responsible for the actions. Mount Image Pro gives the user fast access to scan an image using the latest commercially available virus or Trojan scanners (such as Norton and Mcafee) to test these assertions.

  • Booting a Suspects Computer

    After mounting a forensic image with Mount Image Pro, Virtual Forensic Computing (VFC) by MD5 Ltd allows an investigator to boot a suspects computer and operate it just as the suspect did. This gives the investigator the ability to interact with the crime scene but in a forensic read only environment. It is also useful as a way to provide demonstration to third parties, such as courts and jury's.

  • Other Third Party Tools

    Mount Image Pro enables the use of any third party software tool. Indeed Mount Image Pro technology has been integrated into other commercial applications, including forensic products from Backbone Security and WetStone.

Screenshots


Mip v4 Select Image


Mip v4 Select Image