ImageCacheViewer Hands-on Labs¶
Choose a lab¶
Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
How to use these labs
Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.
Interactive Lab¶
ImageCacheViewer Interactive Lab
Practise a guided ImageCacheViewer workflow in a safe browser simulation with immediate feedback.
- 1Source
- 2Configure
- 3Review
- 4Explain
Choose the authorised, traceable source
The case question is bounded. Select the item that preserves scope and provenance.
Select a source to continue.
URL, title or filename
Do this nowEnter the requested value, then select Search profile. Open the guided hint if you need an exact example.
Guided hintFilter for the filename in the case brief.
Enter the acquisition command, then run the simulation.
Identify the result that answers the case question
Inspect the host, output, expected size and integrity fields. A completed tool run is not automatically a finding.
| Time | Type | URL | State |
|---|---|---|---|
| 10:12:41Z | Download | invoice-review.zip | Complete |
| Background activity outside the case window | |||
Select the row that should be preserved for analysis.
Choose the conclusion supported by the result
Separate the acquired evidence from interpretation and state the next analytical step.
Full Lab¶
ImageCacheViewer Full Lab
Hands-on DFIR proof of concept
Prepare it. Examine it. Explain it.
Use ImageCacheViewer to recover a cached image and record its source URL and cache context, retain the evidence trail and write a bounded finding another analyst can review.
Safety boundary
Use copied profiles. Do not open recovered links or downloads on the analyst workstation.
a copied training browser profile or supplied browser artefact set
a browser observation linked to profile, source artefact, time context, and corroborating evidence
Recommended first
Beginner Core Lab¶
Complete one bounded ImageCacheViewer workflow using the documented source, settings and expected result.
Optional extension
Add a comparison¶
After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.
Full Lab scenario¶
You are the first analyst reviewing a bounded training case. Your task is to recover a cached image and record its source URL and cache context. The result must be understandable to a second analyst who did not watch you perform the work.
01
Activity 1: Prepare the environment¶
- Record the case question, authority and the identity of the isolated training system or evidence source.
- Record the ImageCacheViewer version, provenance, system time and time zone.
- Identify the original material, working location and separate output destination. Confirm that there is enough free space.
- Take or verify a recoverable baseline before changing the training system.
02
Activity 2: Complete the focused task¶
- Restate the investigation question and select only the settings or commands required to recover a cached image and record its source URL and cache context.
- Follow the preserved ImageCacheViewer guide and record any necessary difference in paths, labels or version-specific behaviour.
- Record start and finish times, relevant settings, completion status, warnings and errors.
- Preserve the returned output and keep it attributable to its source and collection context.
03
Activity 3: Review and report¶
- Work from an identified copy and confirm a browser observation linked to profile, source artefact, time context, and corroborating evidence.
- Separate direct tool observations from analyst interpretation. Record missing fields, unavailable material and alternative explanations.
- Preserve relevant integrity information, settings or commands and the evidence needed for another analyst to reproduce the result.
- Write a bounded conclusion with observation, interpretation, confidence and limitations, then clean up the disposable environment.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.
-
Core completion¶
Required to demonstrate a safe, attributable workflow.
-
Good analyst practice¶
Supplementary records that improve reproducibility and review quality.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.