Hi all. Not sure if this has been discussed or not, but I'll give my 2cents based upon my experience thus far with mounting E01 images from FTK on a Win7 machine. I have observed that you do get access is denied after mounting the image via FTK. My solution is to open cmd.exe as Admin, go to Task Manager, kill explorer.exe, and then type explorer.exe in the cmd windows and enter. This will give you a new explorer shell with elevated privs. After this you can view the contents of all the folders of the mounted image without getting the access id denied error message.
I am new to plaso, but have been using log2timeline in the SIFT for a while, which is easy as the install is there already. However, I want to get this working in Win7 natively but seem to be struggling a bit getting it to work.
I do have a request, if someone will be so generous...here is my situation, I have mounted the EWF image via FTK to E:\ now I want to do a kitchen sink parse of the mounted image with l2t and dump the output to a .csv file. However, I just can't seem to get it going.
Any change someone can give me a nudge here to get me going? Thank you.