Mount point. Pt 2

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Mount point. Pt 2
Hello! We decided to talk about disk mounting again. Today we’ll tell you how to work with LVM containers. Here’s a short manual so you don’t have to Google and waste time during an urgent investigation.
1️⃣ Step 1. Check information about the existing binary image:
fdisk -l ./source.raw
(How to get a binary image from VMDK, VDI, VHD and other formats, we wrote about here).
We see:
Device Boot Start End Blocks Id System
disk.img1 * 1 13 104391 83 Linux
disk.img2 14 2491 19904535 8e Linux LVM
Here we are interested in partition 8e — Linux LVM.
2️⃣ Step 2. Mount the source image to a virtual loop interface:
sudo losetup -f -P source.raw
As a result, a virtual loop-device should appear. Check its parameters:
sudo lsblk -f
loop20
├─loop20p1
├─loop20p2 ext4 1.0 f32150ec-1a4e-4871-9c1b-43219f525536
└─loop20p3 LVM2_member LVM2 001 iiB6Sv-7IZv-k329-ednM-h4Nr-tZQk-NJrMoE
(*device indices may differ depending on hardware configuration)
3️⃣ Step 3. Scan the obtained device for LVM partitions:
sudo pvscan --cache
We see:
pvscan[3874] PV /dev/loop20p3 online.
After that, run the command:
sudo vgs (to view volume groups):
ubuntu-vg 1 1 0 wz--n- 18.22g 0
and sudo lvs (to view logical volumes):
ubuntu-lv ubuntu-vg -wi-a----- 18.22g
4️⃣ Step 4. Activate the LVM partition:
sudo vgchange -ay
1 logical volume(s) in volume group "ubuntu-vg" now active
5️⃣ Step 5. Then mount using the well-known mount command (remember the -ro flag to avoid making changes):
sudo mkdir /mnt/lvm-disk
sudo mount -ro /dev/mapper/ubuntu--vg-ubuntu--lv /mnt/lvm-disk
As a result, we get the mounted partition in the specified folder and perform further actions.
To unmount LVM, use the reverse sequence of commands:
sudo umount /mnt/backup-restore (unmount the partition)
sudo lvchange -an /dev/mapper/ubuntu--vg-ubuntu--lv (deactivate LVM)
sudo losetup -d /dev/loop20 (detach the device)
sudo pvscan --cache (scan the disk system to update the state)
Another post for the collection of useful manuals. To be continued!
#tip #dfir
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



