-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Windows Forensics Analyst Field Guide
By :

To prepare for this book’s exercises, we will work now on deploying a forensics lab with tools that we will utilize during our investigation of each artifact. In this section, we will show you how to install a VMware workstation to deploy our Windows OS (Windows 10).
Note that to prepare labs for this book, I will proceed and deploy a lab virtual machine on a VMware product; if you prefer to use VirtualBox, you can apply the same steps when installing Windows OS.
Let’s start with installing Workstation 17 Pro:
https://www.vmware.com/mena/products/workstation-pro/workstation-pro-evaluation.html
Figure 1.9 – VMware Workstation download page
Figure 1.10 – VMware Workstation installation process – part 1
Figure 1.11 – VMware Workstation installation process – part 2
Figure 1.12 – VMware Workstation installation process – part 3
Figure 1.13 – VMware Workstation installation process – part 4
Figure 1.14 – VMware Workstation installation process – part 5
Once Workstation 17 Pro is installed, you can see the Library pane and the Home tab, which shows your virtual machines:
Figure 1.15 – VMware Workstation interface
For the next exercise, let’s start making a Windows ISO file to install on a virtual machine:
Figure 1.16 – Preparing Windows 10 ISO – part 1
Figure 1.17 – Preparing Windows 10 ISO – part 2
Figure 1.18 – Preparing Windows 10 ISO – part 3
Figure 1.19 – Preparing Windows 10 ISO – part 4
The next exercise is to install Windows 10 as a virtual machine on Workstation 17 Pro:
Figure 1.20 – Windows 10 installation process – part 1
Figure 1.21 – Windows 10 installation process – part 2
DFIR Labs
, assign 60 GB
as the virtual HDD, and select a minimum of 4 GB
of RAM:Figure 1.22 – Virtual machine settings
During the exercises in the next chapters, we will start downloading and setting up the tools to use for our investigation and artifact analysis each tool will be presented with link to download.
Now we have completed setting up our virtual machine. Let’s take a snapshot of it just in case we need to revert and avoid re-installing it.
Figure 1.23 – Windows 10 ready for a lab
In conclusion, setting up a forensic lab is a critical step toward conducting effective digital forensics investigations. A properly configured forensic lab can help ensure the integrity of evidence, streamline the investigation process, and increase the chances of successful investigations. By following the guidelines and best practices outlined in this chapter, forensic analysts can establish a reliable and efficient forensic lab that can meet the demands of modern digital investigations.
Change the font size
Change margin width
Change background colour