Mount an EWF Forensic Image Safely with ewfmount

ewfmount exposes an Expert Witness Compression Format (EWF) image through a mount point so you can inspect it without copying it first. That mount point is temporary: this guide walks through setting it up, inspecting the image read-only, and unmounting cleanly. The examples use ewfmount 20140814 from ewf-tools 20140814-1build3, the version installed on this machine.

Allow about fifteen minutes for a small image, plus the time needed to inspect it. You need the complete EWF segment set, a directory where you can create a mount point, and a shell. This guide is for mounting and inspection. It does not modify the evidence image, but anything you do to files exposed through the mount can have forensic consequences, so keep analysis commands read-only.

1. Check the installed command

Confirm the binary and package version before relying on option behaviour. These are ordinary read-only commands:

$ command -v ewfmount
/usr/bin/ewfmount
$ ewfmount -V
ewfmount 20140814
$ dpkg-query -W -f='${Package} ${Version}\n' ewf-tools
ewf-tools 20140814-1build3

The local manual describes two positional arguments: an EWF source image, or the first file in a segment set, followed by the mount-point directory. The command-line help calls the first argument image. If your evidence is split across files such as case.E01, case.E02 and later segments, keep the whole set together and pass the first segment, not a random member.

Checkpoint: run ewfmount -h if you need to confirm the syntax on another installation. The installed help documents raw as the default input format and files as the restricted format for logical volume files.

2. Prepare a dedicated mount point

Choose a new, empty directory outside the evidence directory. Creating the directory changes local system state, but it does not change the image:

$ mkdir -p /tmp/ewfmount-case
$ find /tmp/ewfmount-case -mindepth 1 -maxdepth 1 -print
$ test -z "$(find /tmp/ewfmount-case -mindepth 1 -maxdepth 1 -print -quit)" && echo 'mount point is empty'
mount point is empty

Replace /tmp/ewfmount-case with a controlled analysis path if the image must survive a reboot or a long examination. Do not point ewfmount at a directory containing unrelated files. A mounted filesystem can hide those files until unmounted, which is an avoidable distraction.

3. Mount the EWF image

Run the command with the first segment and the directory you prepared:

$ ewfmount /evidence/case.E01 /tmp/ewfmount-case

On this version, the normal invocation stays in the foreground while the filesystem is mounted. Leave that terminal running. Open a second terminal for inspection. If the command reports a permission or FUSE error, retrying with elevated privileges may be necessary on your host:

$ sudo ewfmount /evidence/case.E01 /tmp/ewfmount-case

Use sudo only when the local FUSE setup requires it. It grants the mount process extra authority; it does not validate the evidence and does not repair a missing segment. Do not use an arbitrary -X value copied from a different FUSE implementation. The manpage only says that -X passes extended options to the subsystem.

Checkpoint: from the second terminal, verify that the mount is active:

$ mountpoint /tmp/ewfmount-case
/tmp/ewfmount-case is a mountpoint
$ findmnt --target /tmp/ewfmount-case

The exact findmnt line depends on your kernel and FUSE configuration. If mountpoint does not confirm a mount, stop and read the first terminal's error before inspecting paths below it.

4. Identify the exposed data before opening it

The ewfmount manual does not promise a fixed filename inside the mount, so do not hard-code one from memory. List the top level and identify the result:

$ find /tmp/ewfmount-case -maxdepth 1 -mindepth 1 -printf '%f\n'
$ find /tmp/ewfmount-case -maxdepth 1 -mindepth 1 -exec file --brief -- {} \;

Use the path reported by your own listing in subsequent read-only tools. For example, if the listing shows EXPOSED_DATA, substitute /tmp/ewfmount-case/EXPOSED_DATA for /path/to/exposed-data here:

$ stat /path/to/exposed-data
$ file /path/to/exposed-data
$ sha256sum /path/to/exposed-data

Hashing or reading a large exposed object can take time and will cause the image to be read. It should not write to the source image, but record what you ran and when if the work is part of an examination. Avoid editors, repair utilities and commands that mount the exposed filesystem a second time unless your procedure explicitly requires them.

5. Choose the input format deliberately

The default format is raw. That is the normal starting point when the EWF represents a raw storage image. The alternative is files, which the manual restricts to logical volume files:

$ ewfmount -f raw /evidence/case.E01 /tmp/ewfmount-case
$ ewfmount -f files /evidence/volume.E01 /tmp/ewfmount-volume

Do not add -f files because a previous case used it. Select it from the evidence format and your analysis plan. If the command says that the input format is unsupported or that it cannot open the source image, first check the filename, extension, permissions and complete segment set:

$ ls -l /evidence/case.E0?
$ test -r /evidence/case.E01 && echo 'first segment is readable'
$ ewfmount -v /evidence/case.E01 /tmp/ewfmount-case

-v sends verbose diagnostics to standard error and keeps ewfmount in the foreground. It is useful for a failed mount, but it does not change the input format or make a broken segment set usable. The local program also reports errors such as an unresolvable filename; treat those as input or path problems before changing permissions.

6. Unmount and recover cleanly

Finish every read before unmounting. In the terminal running ewfmount, stop the foreground process with Ctrl-C. Then confirm the mount has gone away:

^C
$ mountpoint /tmp/ewfmount-case
/tmp/ewfmount-case is not a mountpoint

If it remains mounted, use the FUSE unmount command available on your system, commonly fusermount3 or fusermount:

$ fusermount3 -u /tmp/ewfmount-case
$ mountpoint /tmp/ewfmount-case

Do not delete the mount-point directory while it is mounted. If a process reports that the mount is busy, return to the second terminal, leave the directory, and close programs that still have files open:

$ cd /tmp
$ fuser -vm /tmp/ewfmount-case
$ fusermount3 -u /tmp/ewfmount-case

Only after the path is no longer a mountpoint may you remove the empty temporary directory. That removal is optional and irreversible for the directory itself, but it does not delete the EWF image:

$ rmdir /tmp/ewfmount-case

Done means