Portable Arsenal Image Mounter Pro 3.12.344

Arsenal Image Mounter Pro is a professional-grade forensic disk image mounting utility designed for digital investigators, incident responders, law enforcement, corporate security teams, and cybersecurity professionals who require read-only access to the complete contents of forensic disk images, virtual disks, archives, and raw memory captures as fully functional Windows drives without risky write operations, data alteration risks, or complex virtual machine overhead.
Arsenal Image Mounter mounts the contents of disk images as complete disks in Windows®. As far as Windows is concerned, the contents of disk images mounted by Arsenal Image Mounter are real SCSI disks, allowing users to benefit from disk-specific features like integration with Disk Manager, launching virtual machines (and then bypassing Windows authentication), managing BitLocker-protected volumes, mounting Volume Shadow Copies, and more.
Many Windows®-based disk image mounting solutions mount the contents of disk images as shares or partitions, rather than complete (a/k/a “physical” or “real”) disks, which limits their usefulness to digital forensics practitioners and others. Arsenal Image Mounter mounts the contents of disk images as complete disks in Windows. As far as Windows is concerned, the contents of disk images mounted by Arsenal Image Mounter are real SCSI disks, allowing users to benefit from disk-specific features like integration with Disk Manager, launching virtual machines (and then bypassing Windows authentication), managing BitLocker-protected volumes, mounting Volume Shadow Copies, and more.
This Windows-native powerhouse mounts over 30 disk image formats—including EnCase E01/EX01, FTK FTK Imager (including FTK encryption), Raw/DD, AFF4, VMDK, VHD/VHDX, QCOW2, EWF, LVM/LVM2, and VMware/VirtualBox snapshots—directly as assignable drive letters or complete virtual SCSI disks recognized natively by Windows Disk Management, enabling seamless integration with analysis tools like Autopsy, X-Ways Forensics, EnCase, Magnet AXIOM, Registry Explorer, and bulk_extractor while preserving perfect chain-of-custody through MD5/SHA-1/SHA-256 hash verification, bit-for-bit read-only mounting, and comprehensive logging of all mount/unmount operations.
Whether mounting encrypted BitLocker volumes (with recovery key/password support), accessing Volume Shadow Copies via multiple bypass methods, launching virtual machines directly from evidence images for live credential extraction, decrypting hibernation files (hiberfil.sys), reconstructing registry hives, or mounting nested differencing disks from corporate forensic collections spanning terabytes, Arsenal Image Mounter Pro delivers enterprise-grade reliability with military-spec precision, eliminating the guesswork and frustration of traditional mounting workflows while supporting air-gapped analysis environments, ARM64 virtualization, Windows S-Mode bypasses, and remote agent deployment across distributed investigation teams.
Core Mounting Engine and Format Mastery
Arsenal Image Mounter Pro’s patented mounting architecture transforms static forensic artifacts into live, queryable filesystems through a dual-mode engine: Standard Mounting exposes image partitions as read-only NTFS/FAT/exFAT/ext4/HFS+/APFS volumes assignable to Windows drive letters (Z:, Y:), while Complete Disk Mounting presents entire raw images as virtual SCSI devices indistinguishable from physical hardware—enabling Disk Management formatting visibility, Windows Backup integration, BitLocker volume recognition, and third-party forensic tool compatibility without format conversion risks. The engine auto-detects filesystem boundaries via partition table parsing (MBR/GPT/Apple Partition Map/Dynamic Disks), validates integrity against embedded CRCs/hashes, and supports compressed/sparse images without full decompression, preserving evidence authenticity across EWF-compressed acquisitions, VMware VMDK delta chains, and Hyper-V differencing disks.
Universal Format Support spans the forensic ecosystem:
- Traditional Images: EnCase E01/EX01/L01 (segmented/compressed/encrypted), FTK FTK Imager (RAW/FTK encryption), Raw/DD (.dd/.raw/.bin)
- Open Standards: AFF4 (advanced forensic format 4), EWLF (expert witness compressed)
- Virtualization: VMDK (VMware snapshots/deltas), VHD/VHDX (Hyper-V/dynamic), QCOW2 (QEMU/KVM), VDI (VirtualBox)
- Enterprise: LVM/LVM2 (logical volume manager), ZFS (with partial read support)
- Memory: Raw memory dumps, hibernation files (hiberfil.sys), pagefile.sys analysis
Mount times scale linearly—1TB E01 in 45 seconds on NVMe SSDs, 500GB VMDK chain in 90 seconds—thanks to intelligent caching, parallel partition detection, and on-demand block reading that bypasses full image extraction.
Professional Mode: Enterprise Forensic Capabilities
While the free edition handles basic mounting, Arsenal Image Mounter Pro unlocks mission-critical features for serious investigations:
Virtual Machine Launcher: Right-click any mounted image → “Launch in VM” instantly boots evidence drives in pre-configured Hyper-V/VMware Workstation/Player environments, often auto-logging into locked Windows systems via Windows Authentication Bypass that injects cached domain credentials, LSASS memory extraction, or SAM hive manipulation without passwords. Linux Password Bypass mounts /etc/shadow-enabled ext4 volumes directly, enabling root access to *nix acquisitions.
Volume Shadow Copy Mastery: Three mounting methods—Standard VSS (Windows native), NTFS Driver Bypass (reads locked $SYSTEM_VOLUME_INFORMATION without admin/VSS service), Complete Disk VSC (mounts shadow copies as independent SCSI disks)—recover deleted files, previous versions, and time-stamped backups from locked corporate endpoints. Multiple VSS Chains coexist simultaneously (VSS1 at X:, VSS2 at Y:).
BitLocker Decryption: Password/recovery key mounting, Windows File System Driver Bypass for locked corporate volumes, Export Decrypted saves fully unlocked images for air-gapped analysis.
Hibernation Recon: Automatically extracts and mounts hiberfil.sys as live memory filesystems, preserving volatile artifacts (RAM Slack, pagefile overlays) for volatility analysis.
Registry Recon: Mounts SYSTEM/SOFTWARE/SECURITY hives from mounted images, launches Registry Explorer with full live viewing.
HBIN Recon: Parses Windows Hibernation Intermediate files for credential recovery.
Hive Recon: Direct registry hive mounting as queryable volumes.
Advanced Mounting Options and Evidence Integrity
Every mount operation offers granular control:
Read-Only Guarantee: Block-level copy-on-read emulation prevents any evidence corruption, verified via runtime hash recalculation.
Drive Letter Assignment: Auto-assign sequential letters (Z:\ → Y:\ → X:) or manual specification.
Mount as Folder: Expose partitions within existing NTFS drives as reparse points.
Offset Mounting: Skip header bytes for custom/raw images.
Split/Segment Handling: Auto-concatenates E01/L01 segments across folders/drives.
Compression Bypass: Mount .E01/.AFF4 without extraction.
Hash Verification: Embedded MD5/SHA-1/SHA-256 validation at mount time, continuous integrity monitoring, exportable verification reports (.csv with block-level granularity).
Logging and Audit: Immutable operation logs timestamp mounts, access patterns, dismounts—EDRM-compliant for court exhibits.
Remote Agent and Distributed Forensics
AIM Remote Agent enables distributed mounting across enterprise networks: deploy lightweight .NET agents to target endpoints (Windows 10/11, Server 2019/2022, ARM64 Windows), mount remote disk images as local drives, or stream mounted volumes back to analyst workstations via high-speed SMB/NFS. Multiple Simultaneous Connections support parallel investigations—Agent1 mounts Suspect1 E01, Agent2 handles Suspect2 VMDK simultaneously.
PowerShell Module (Import-Module Arsenal.Image.Mounter) exposes cmdlets: Mount-AIMImage -Path evidence.E01 -Letter Z -Mode CompleteDisk, Get-AIMMountedDrives, Dismount-AIMImage -All.
AIM CLI provides headless mounting for automation/CI/CD pipelines.
Windows S-Mode and ARM64 Virtualization
Windows S-Mode Bypass (x64/ARM64) mounts forensic images on locked-down Microsoft Store-only systems, enabling field investigators to analyze evidence on Surface Pros without admin escalation. ARM-on-ARM Virtualization boots Windows on ARM evidence images natively on Snapdragon X Elite/Plus devices, preserving architecture fidelity for mobile forensics.
Specialized Forensic Workflows
Corporate Incident Response: Mount locked BitLocker laptops remotely, extract VSS backups, launch VM for live credential dumping.
Law Enforcement: E01 chain from Cellebrite acquisition → mounted NTFS → Registry Explorer → timeline reconstruction.
Military: Air-gapped AFF4 mounting from DoD TAC2000, hibernation analysis for OPSEC violations.
E-Discovery: Mount 50TB mailserver VHDX, VSS recovery of deleted PSTs.
Ransomware: Mount encrypted .locker variants as raw volumes for decryption key hunting.
Chain-of-Custody and Reporting
Mount Reports (.PDF/HTML) document image hashes, mount parameters, filesystem details, accessible partitions. Access Logs track every file read/open operation. Dismount Verification confirms clean teardown with final hash validation.
Performance and Scalability
NVMe-Optimized: 2.5GB/s sequential reads from mounted E01s.
Multi-Core: 32-thread partition detection.
Memory Efficient: 500MB RAM for 10 concurrent mounts.
Scalability: Unlimited simultaneous mounts (license-limited).
User Interface Excellence
Clean, forensic-focused GUI: Image Browser (drag-drop acquisition files), Mount Queue (batch operations), Mounted Volumes Panel (real-time stats: size/free, FS type, access count), Log Viewer (filterable events). Dark Theme, high-DPI scaling, keyboard shortcuts.
Deployment and Licensing
Portable Edition: USB-bootable, no install required.
Enterprise Licensing: Named users, concurrent seats, volume discounts.
Air-Gapped Compatible: Offline activation, no phoning home.
System Requirements: Windows 10/11 (x64/ARM64), Server 2016+, .NET 8/9/10.
Free Mode Baseline
Mounts RAW/E01/AFF4/VMDK/VHD as drives/volumes—Pro unlocks VM bypasses, VSS mastery, remote agents.