using the forensic vm hard drives

2
USING THE FORENSIC VM HARD DRIVES 1. Plug the USB hard drie i!t" the #a$le "! the de%&. D" !"t u% the 'r"!t USB ("rt% a% the%e are %l")er. Ma&e %ure that the USB hard drie i% the "!l* USB %t"rage dei#e (lugged i!. +. Start , VMware WorkStation For Forensics - 'r" the VM/are '"lder "! the Start Me!u 0. Fr" the File e!u i! VM/are #h""%e O(e! a!d !d U$u!tu "r /i!d")% 2 'r" the I3 drie 4. The r%t ru! "' either )ill re5uire *"u t" %et u( *"ur hard drie. a. F"r /i!d")% i. O! the le't "' the VM/are )i!d") #li#& ,Edit virtual machine settings - ii.Sele#t , Hard Disk (SCSI)- a!d #li#& Re "e iii.Ch""%e add a!d %ele#t , Hard Disk - a!d #li#& Ne6t i. Ma&e %ure SCSI i% %ele#ted a!d the #li#& Ne6t . Ch""%e ,se a !h"sical disk - a!d #li#& Ne6t i.Sele#t , #h"sicalDrive $% a!d ,se individual !artitions - a!d the! #li#& Ne6t

Upload: james-webb

Post on 04-Nov-2015

5 views

Category:

Documents


0 download

DESCRIPTION

How to use uwe forensic harddrives

TRANSCRIPT

USING THE FORENSIC VM HARD DRIVES

1. Plug the USB hard drive into the cable on the desk. Do not us the front USB ports as these are slower. Make sure that the USB hard drive is the only USB storage device plugged in.2. Start VMware WorkStation For Forensics from the VMWare folder on the Start Menu3. From the File menu in VMWare choose Open and find Ubuntu or Windows 7 from the I: drive4. The first run of either will require you to set up your hard drive.a. For Windowsi. On the left of the VMWare window click Edit virtual machine settings

ii. Select Hard Disk (SCSI) and click Removeiii. Choose add and select Hard Disk and click Nextiv. Make sure SCSI is selected and the click Nextv. Choose Use a physical disk and click Nextvi. Select PhysicalDrive 1 and Use individual partitions and then click NextIf PhysicalDrive1 is not available close VMWare and make sure the USB drive is plugged in and go back to step 1vii. Select Partition 0, Partition 1 and Partition 2 and click Next viii. Click Finish to save the disk configuration and then choose OK on the Virtual Machine Settings dialogue

b. For Linux i. Follow the same procedure as above but when selecting partitions choose Partition 0 and Partition 1 ONLY 5. You can now power on your virtual machines.