Windows Images ANY ...
 
Notifications
Clear all

Windows Images ANY Windows VMs

5 Posts
4 Users
0 Reactions
596 Views
kleanchap
(@kleanchap)
Active Member
Joined: 17 years ago
Posts: 19
Topic starter  

I want to get a little bit better at Windows forensics skills. My core skills are in Linux/Unix and networking. Where can I find some Windows disk images for using with forensics tools?

Also, where can I find Windows XP VM images? I have Vista but XP seems to been more widely used. Lot of the questions about windows forensics is dealing with Windows registry and filesystem metadata. So I would lilke to play with a XP VM system.

Thank you in advance.

K


   
Quote
bshavers
(@bshavers)
Estimable Member
Joined: 20 years ago
Posts: 211
 

You may want to have your own licensed copy of XP to work with. There are images available on the internet, but the majority are not going to be full installs of an OS.

A good method of validating and testing forensics is also to work on an image on which you know what 'evidence' exists (such as data you have personally planted on the drive).

You can fairly quickly and easily create a VM with VMware from a XP install disk, seed it with known evidence such as emails, deleted files, etc.., and then image it out with FTK Imager for analysis.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Not a VM, but it can be booted w/ LiveView
http//www.cfreds.nist.gov/Hacking_Case.html

If you just want images
http//www.forensickb.com/search?q=practical

Haven't tried this one
http//www.shortinfosec.net/2008/07/competition-computer-forensic.html


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Just for the record, there are VM images available (for testing different versions of IE)
http//www.microsoft.com/downloads/details.aspx?FamilyId=21EABB90-958F-4B64-B5F1-73D0A413C8EF&displaylang=en
but they are for MS own Virtual PC, which is notoriously slower than VmWare or better even, VirtualBox.

jaclaz


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Just a few seconds on Google found this
http//www.petri.co.il/virtual_import_virtual_server_and_pc_to_vmware.htm

Once you convert the VPC system to a VMWare .vmdk file, you don't even have to boot it if you just want an image. All you need to do is open it in FTK Imager and acquire an image.


   
ReplyQuote
Share: