Talk With an Expert

Reverse Engineering Virtual Machine File System 6 (VMFS 6)

Reverse Engineering Virtual Machine File System 6 (VMFS 6) (PDF, 2.30MB)Published: 19 Nov, 2020
Created by:
Michael Smith

Virtual Machine File System (VMFS) 6 is a proprietary file system. The file system's proprietary nature means that many forensic applications are unable to parse the file system. There is a lack of support because proprietary file systems do not have to follow an accepted standard and can make modifications that break forensic tools with any release. This instability means that maintaining parsers for these file systems can become costly very quickly. This vacuum of support for proprietary file systems has created an opportunity for open-source utilities to grow in ways that support parsing these file systems. Skilled forensic examiners scour the open-source community and publicly available research for parsers and digital artifacts analyses when they encounter file systems or files unsupported by large forensic applications. The goal of this research is two-fold. First, to increase the understanding of VMFS 6 with its myriad digital artifacts. Second, to conclusively determine the recoverability of a deleted file.