This presentation will be about the problems we are facing when forensic research has to be done on environments which are virtualized. What are the differences between 'tradional' system forensics, what techniques & tools can be used. Which files are important when performing forensic research on Citrix & VMWare environments? What about VHD file format with Windows 7 and what do we need for future research?