This project focuses on the forensic analysis of VMDK files for my bachelor’s thesis. It involves examining virtual machine disk images to extract the bytes and calculate the entropy (more tests will follow) to highlight the non affected areas after a ransomware attack.