Getting Started with SUSA¶
Prepare a controlled Windows analysis environment before installing tools or handling evidence. These four guides form one setup journey; complete the parts that apply to your workstation and record any differences from the reference build.
Choose your setup task¶
01Create a Windows VMBuild an isolated Windows workstation for SUSA tools, evidence handling and lab activity.Complete when Windows is installed, updated and protected by a clean snapshot.Recommended first · Windows · VM required 02Install WSLAdd the Linux environment required by selected command-line and analysis workflows.Complete when the distribution opens and its packages can be updated.Windows feature · Administrator access 03Improve forensic visibilityConfigure the training workstation so useful forensic activity is recorded and observable.Complete when the documented visibility controls are enabled and verified.Training configuration · Record changes 04Create tool shortcutsOrganise frequently used SUSA tools so analysts can find and launch the correct executable.Complete when shortcuts point to the recorded tool locations and architectures.Usability · Repeatable workspace
Use the journey as a baseline
Host capabilities and organisational controls differ. Record VM resources, Windows version, snapshots, enabled features and configuration exceptions so another learner can understand and reproduce your environment.
Recommended order¶
Start with the Windows VM when you need a disposable lab. Install WSL only for workflows that require it. Apply visibility enhancements before generating test activity, then create shortcuts after tool locations and architectures are stable.