Hi All,
I am working on disk imaging a computer that runs a software-based artwork at my institution. The computer is a Debian Linux system, and through Disktype, we found out that the main partition on the computer's SSD uses the BTRFS file system.
We created an EWF disk image using Guymager which seemed to work successfully. We tried to run fiwalk on the disk image to create a DFXML file of the contents and received an error message (TSK_error ‘Cannot determine file system type’) presumably when fiwalk tried to read the BTRFS partition. Could the fiwalk error potentially mean that this area of the disk is encrypted? Would there be a way to determine this either on the original computer or by looking at the disk image?
We also tried to mount the EWF file but have so far been unsuccessful. Have others been able to successfully mount BTRFS disk images within BitCurator? If so, do you have any advice?
For reference, I have attached the output of Fiwalk and the output of Disktype, which shows the number of partitions and the BTRFS file system.
Thanks in advance for your advice,
Jonathan
Jonathan Farbowitz (he/him/his)
Associate Conservator of Time-Based Media
Photograph Conservation
212-396-5123The Metropolitan Museum of Art
1000 Fifth Avenue
New York, NY 10028
@metmuseum
metmuseum.org