Disk Image Converter & Hash Verifier (E01, DMG, VHDX, VMDK to Raw)
Open forensic and virtual disk images, check their hashes and turn them into raw images.
Free preview.
- Free preview: the image’s format details, its partition map, and the MD5, SHA-1 and SHA-256 of the whole disk checked against every value the image stores.
- Locked until you unlock it: download and saving to your device.
- Unlock: Ultimate pass, ₹1,199 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Choose the image
Partition map
| # | Starts at byte | Size | Partition type | File system |
|---|
Find deleted files on this disk
Hashes and checks
Show each value
Save as a raw image
Save it on a different drive from the one you are recovering. The raw image is as large as the whole disk.
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
About the Disk Image Converter & Hash Verifier (E01, DMG, VHDX, VMDK to Raw)
Imaging programs and virtual machines rarely save a disk as a plain sector-by-sector copy: EnCase and FTK Imager write E01 files, macOS writes DMG images, Windows and Hyper-V VHD and VHDX files, VMware VMDK disks, QEMU QCOW2 and VirtualBox VDI. This page opens any of them in your browser, shows what it holds, and reads the disk inside without unpacking a copy first.
You see the image’s details (an E01 also shows its case number, examiner and acquisition time), the partition map of the disk, and, after one pass over the whole disk, its MD5, SHA-1 and SHA-256. Every value the image stores is checked on the way: an E01’s MD5 and SHA-1 and the checksum of each chunk, a DMG’s CRC-32 for each partition and for the file, a VHDX file’s header checksums. Paste the hash from an imaging log to compare it.
Without a pass this is a free preview: the details, the partition map and every hash and check are shown in full. Saving the disk as a raw .img image (which every recovery page and forensic tool reads) and the PDF report need an Ultimate pass.
How to use it
- Choose the image file. For an image in several files choose them all together: the E01 with its .E02, .E03 … segments, a VMware descriptor .vmdk with its -s001 or -flat parts, or a differencing VHD, VHDX, QCOW2 or VDI with its parent.
- Read the image’s details and its partition map: each partition’s start, size, type and file system.
- Press Compute hashes. The page reads the whole disk once (a large image takes a while; the progress bar shows the time left) and lists the MD5, SHA-1 and SHA-256, with every value the image stores compared with them.
- To check the image against an imaging log, paste the logged hash into Compare with a hash you have.
- With an Ultimate pass, save the disk as a raw image on a different drive from the one you are recovering, or download the PDF report.
- Open the raw image in a recovery page to find deleted files: SD Card & USB Drive Recovery for FAT and exFAT, NTFS Deleted File Recovery, File Recovery for Mac Drives for APFS and HFS+, File Recovery for Linux Drives for ext4, or the deep scan for any file system.
Examples
stick.E01 and stick.E02 (made with an imaging program, compressed)
EnCase / Expert Witness (E01) · 2 segments · 32 KB chunks · MD5 stored in the image: matches the MD5 computed from the disk
The hashes describe the disk inside the image, so they are the same as the ones the imaging program logged for the stick itself.
backup.dmg (UDZO, zlib-compressed)
GUID partition table · partition 1 “EFI System” · partition 2 Apple HFS+ · CRC-32 of every partition: matches · 13.9 MB left out as unused space
A compressed DMG that macOS converts from a disk keeps only the space in use, so deleted files are not in it. For recovery, image the disk as “DVD/CD master” (every sector) instead.
vm-checkpoint.avhdx and vm.vhdx chosen together
VHDX virtual hard disk, differencing · parent found · the disk as the virtual machine saw it at that checkpoint
Common uses
- Turning an E01, DMG, VHDX or VMDK image into a raw image that recovery pages and forensic programs open.
- Checking that a copied or downloaded disk image is intact: its stored hashes and checksums, or the hash in an imaging log.
- Looking inside a virtual machine’s disk (its partitions and file systems) without starting the virtual machine.
- Recording a disk image’s details, partitions and hashes in a PDF report.
The formats it reads
- E01 (EnCase / Expert Witness, also S01 from SMART): chunks compressed with zlib or stored with an Adler-32, in one or more segments (.E01, .E02 … .EAA …).
- DMG (Apple disk images): read-only (UDRO) and compressed with ADC (UDCO), zlib (UDZO), bzip2 (UDBZ) or LZFSE (ULFO). A read-write DMG is already a raw image.
- VHD (fixed, dynamic and differencing) and VHDX (fixed, dynamic and differencing; a file Hyper-V did not close properly has its log replayed in memory first, as Hyper-V would, without changing the file).
- VMDK (VMware): monolithic or split, sparse or flat, the stream-optimized disks of OVA and OVF exports (an .ova file is a tar archive: take the .vmdk out of it first), and snapshot (delta) disks with their parents.
- QCOW2 (QEMU, KVM, Proxmox; versions 2 and 3, compressed clusters and backing files) and VDI (VirtualBox, with snapshots).
- Raw images (.img, .dd, .raw, .bin, .iso, .cdr) and raw images saved in parts (.001, .002 …), for the partition map and the hashes.
The readers follow the published descriptions of these formats: Microsoft’s VHDX specification, QEMU’s QCOW2 format, and libyal’s description of the EWF format. LZFSE is decoded with a port of Apple’s reference implementation (BSD licence).
Why the hashes match the original disk
The page hashes the disk inside the image, not the image file. So an E01’s MD5 is the MD5 of the drive that was imaged: the value the imaging program logged, and the value of any raw image of the same drive. Two images of one disk in different formats (an E01 and a raw image, a VMDK and the VHDX it was converted to) give the same hashes when they hold the same bytes.
The raw image this page saves is hashed as it is written, so its hashes are those of the file you get.
Images that leave deleted data out
Not every image keeps every sector. A compressed or read-only DMG that macOS converts from a disk leaves out the space the file system marks as unused, so files deleted before the image was made are not in it; the page says how much was left out. A dynamic VHD or VHDX reads blocks that were never written as zeros, and blocks the virtual machine trimmed as zeros too. An E01 or raw image of a whole drive keeps every sector, deleted data included. For recovery, image the drive itself as raw or E01, or as “DVD/CD master” in Disk Utility.
Measured on test images
Disk images that macOS made with hdiutil (UDRO, UDCO, UDZO, UDBZ and ULFO) and virtual disks that qemu-img made (VHD fixed and dynamic, VHDX fixed and dynamic, VMDK monolithic sparse, split sparse, flat and stream-optimized, QCOW2 versions 2 and 3 with and without compression, VDI dynamic and fixed) were read back byte for byte identical to the raw disk they were made from, and every CRC-32 the DMGs store matched. E01 images made with libewf’s ewfacquire (compressed, and uncompressed in two segments) matched the MD5 they store. These images are part of the page’s automated tests.
Limitations
- Not read yet: Ex01 and Lx01 (version 2 of the EnCase format), L01 logical evidence files, E01 images with AccessData encryption, LZMA-compressed DMGs (ULMO), encrypted or segmented DMGs, sparse images and sparse bundles, ESXi snapshot disks (VMFS sparse and SEsparse), and QCOW2 images that are encrypted or compressed with zstd. The page says which it is and how to convert it.
- Saving a raw image needs space for the whole disk on another drive: a 500 GB disk makes a 500 GB file, even when its image is small.
- Chrome and Edge on a computer write the raw image straight into a file of any size. Other browsers can only download what they hold in memory: up to 1 GB, or 512 MB on mobile devices.
- A web page cannot read a disk or memory card directly; this page works on image files only.
- Reading a large image takes time: the page reads and unpacks every sector once for the hashes, and once more to save it.
- This is not a court-validated forensic tool, and it makes no evidentiary claims. Keep the original image, and check important hashes with a second tool.
Privacy
The image files are read by your browser on your device, a few megabytes at a time, in a background worker; nothing is uploaded. The raw image is written only where you choose to save it.
Frequently asked questions
What do I get without a pass?
Without a pass, Disk Image Converter & Hash Verifier (E01, DMG, VHDX, VMDK to Raw) shows the image’s format details, its partition map, and the MD5, SHA-1 and SHA-256 of the whole disk checked against every value the image stores. Until you unlock it, the result can’t be downloaded or saved to your device. An Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
How do I convert an E01 file to a raw (dd) image?
Choose the .E01 file together with all its segments (.E02, .E03 …) and save the disk as a raw image (this needs an Ultimate pass). FTK Imager on Windows can also export an E01 as a raw (dd) image: File, Export Disk Image, image type Raw (dd).
Why is the raw image so much bigger than the E01 or DMG?
Containers compress the disk or leave out what was never written; a raw image holds every sector of the disk, so it is as large as the disk itself.
Does the MD5 here match the one in my imaging log?
It should: both are hashes of the disk’s own bytes. Paste the logged value into Compare with a hash you have. If an E01 stores its MD5, the page compares that too. A different value means the image is of another disk, or has been damaged or changed.
Can I recover deleted files from a DMG?
Only if the DMG kept the unused space of the disk. Compressed and read-only DMGs that macOS converts from a disk leave it out, and the page tells you how much is missing. A raw image (“DVD/CD master” in Disk Utility) keeps every sector.
My VMDK is several files. Which do I choose?
All of them together: the small descriptor .vmdk (the one without “-s001” or “-flat” in its name) and every part it lists. For a snapshot, choose the parent disk’s files too.
Is anything uploaded?
No. The image never leaves your device: the page reads it in pieces with your browser, in a background worker, and works offline once it has loaded.