Skip to content

Forensic Workstation

A dedicated environment for analyzing evidence and malware samples.

Why It Matters

Analyzing evidence on an everyday workstation risks contaminating the evidence, infecting the workstation, and exposing case data. A separate, consistent analysis environment avoids all three and means the tools are ready when they are needed.

Reference

Setup Contents
Windows analysis VM Eric Zimmerman's tools, FTK Imager, Autopsy, KAPE, Sysinternals
Linux analysis VM The SIFT Workstation toolset, Volatility, YARA
Malware analysis VM Isolated networking (host-only or none), snapshots, no shared folders or clipboard

Good practices:

  • Take a clean snapshot and revert to it before each case
  • Keep case data in an encrypted, access-controlled location
  • Keep tools and symbol tables updated between cases, not during them

How I Use It

I keep a Windows VM and a Linux VM ready with the tools on these pages, each with a clean snapshot. Anything that might execute malware runs on a VM with networking disabled, and case data stays off my day-to-day machine.

Resources