Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Windows Forensics Analyst Field Guide

You're reading from  Windows Forensics Analyst Field Guide

Product type Book
Published in Oct 2023
Publisher Packt
ISBN-13 9781803248479
Pages 318 pages
Edition 1st Edition
Languages
Concepts
Author (1):
Muhiballah Mohammed Muhiballah Mohammed
Profile icon Muhiballah Mohammed

Table of Contents (14) Chapters

Preface 1. Part 1:Windows OS Forensics and Lab Preparation
2. Chapter 1: Introducing the Windows OS and Filesystems and Getting Prepared for the Labs 3. Chapter 2: Evidence Acquisition 4. Chapter 3: Memory Forensics for the Windows OS 5. Chapter 4: The Windows Registry 6. Chapter 5: User Profiling Using the Windows Registry 7. Part 2:Windows OS Additional Artifacts
8. Chapter 6: Application Execution Artifacts 9. Chapter 7: Forensic Analysis of USB Artifacts 10. Chapter 8: Forensic Analysis of Browser Artifacts 11. Chapter 9: Exploring Additional Artifacts 12. Index 13. Other Books You May Enjoy

Preparing a lab environment

To prepare for this book’s exercises, we will work now on deploying a forensics lab with tools that we will utilize during our investigation of each artifact. In this section, we will show you how to install a VMware workstation to deploy our Windows OS (Windows 10).

Note that to prepare labs for this book, I will proceed and deploy a lab virtual machine on a VMware product; if you prefer to use VirtualBox, you can apply the same steps when installing Windows OS.

Let’s start with installing Workstation 17 Pro:

  1. Visit the following link to download the trial version of Workstation 17 Pro for Windows (this is the latest version available as of December 2022):

    https://www.vmware.com/mena/products/workstation-pro/workstation-pro-evaluation.html

  1. Click on DOWNLOAD NOW; it will prompt you to save the executable file, as shown here:
Figure 1.9 – VMware Workstation download page

Figure 1.9 – VMware Workstation download page

  1. Now, double-click on the executable file and then click Next:
Figure 1.10 – VMware Workstation installation process – part 1

Figure 1.10 – VMware Workstation installation process – part 1

  1. Once prompted for an end user license, accept it by checking the free trial option and then click Next. It will prompt you to select the path to install Workstation 17 Pro; click on Next once you have selected it:
Figure 1.11 – VMware Workstation installation process – part 2

Figure 1.11 – VMware Workstation installation process – part 2

  1. Select the Desktop and Start Menu Programs Folder options to create a shortcut or add a VMware workstation application to the Start menu:
Figure 1.12 – VMware Workstation installation process – part 3

Figure 1.12 – VMware Workstation installation process – part 3

  1. Now, once we click on Next, it will start installing the application. The process might take a couple of minutes, depending on your system specifications:
Figure 1.13 – VMware Workstation installation process – part 4

Figure 1.13 – VMware Workstation installation process – part 4

  1. The last step for this process is to either select the I want to try VMware Workstation 17 for 30 days option or use a legitimate key to activate your product, and then click on Continue:
Figure 1.14 – VMware Workstation installation process – part 5

Figure 1.14 – VMware Workstation installation process – part 5

Once Workstation 17 Pro is installed, you can see the Library pane and the Home tab, which shows your virtual machines:

Figure 1.15 – VMware Workstation interface

Figure 1.15 – VMware Workstation interface

For the next exercise, let’s start making a Windows ISO file to install on a virtual machine:

  1. Visit the following link and click on Download Now; it will download media creation tools for us to use:

    https://www.microsoft.com/en-us/software-download/windows10

  1. Double-click on the Windows 10 Setup executable and accept the license (the tools will take some time to download, depending on your network speed):
Figure 1.16 – Preparing Windows 10 ISO – part 1

Figure 1.16 – Preparing Windows 10 ISO – part 1

  1. Select the Create installation media (USB flash drive, DVD, or ISO file) for another PC option:
Figure 1.17 – Preparing Windows 10 ISO – part 2

Figure 1.17 – Preparing Windows 10 ISO – part 2

  1. Select the architecture that you want (in our case, we will proceed with 64-bit (x64)):
Figure 1.18 – Preparing Windows 10 ISO – part 3

Figure 1.18 – Preparing Windows 10 ISO – part 3

  1. Now, we will select the ISO file option and the saving path on your local machine to download and create a Windows 10 image:
Figure 1.19 – Preparing Windows 10 ISO – part 4

Figure 1.19 – Preparing Windows 10 ISO – part 4

The next exercise is to install Windows 10 as a virtual machine on Workstation 17 Pro:

  1. Click on Click Virtual Machines > Create VM and select the Typical installation option:
Figure 1.20 – Windows 10 installation process – part 1

Figure 1.20 – Windows 10 installation process – part 1

  1. Click on the Installer disc image file (iso) option, as shown in the following screenshot, and select the path for the Windows 10 ISO file:
Figure 1.21 – Windows 10 installation process – part 2

Figure 1.21 – Windows 10 installation process – part 2

  1. Click Next and name the virtual machine DFIR Labs, assign 60 GB as the virtual HDD, and select a minimum of 4 GB of RAM:
Figure 1.22 – Virtual machine settings

Figure 1.22 – Virtual machine settings

  1. The last step is to follow the Windows installation guide and run the virtual machine, for which we are all set up now.

During the exercises in the next chapters, we will start downloading and setting up the tools to use for our investigation and artifact analysis each tool will be presented with link to download.

Now we have completed setting up our virtual machine. Let’s take a snapshot of it just in case we need to revert and avoid re-installing it.

Figure 1.23 – Windows 10 ready for a lab

Figure 1.23 – Windows 10 ready for a lab

In conclusion, setting up a forensic lab is a critical step toward conducting effective digital forensics investigations. A properly configured forensic lab can help ensure the integrity of evidence, streamline the investigation process, and increase the chances of successful investigations. By following the guidelines and best practices outlined in this chapter, forensic analysts can establish a reliable and efficient forensic lab that can meet the demands of modern digital investigations.

You have been reading a chapter from
Windows Forensics Analyst Field Guide
Published in: Oct 2023 Publisher: Packt ISBN-13: 9781803248479
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}