MZCacheView Hands-on Labs¶
Choose a lab¶
Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
How to use these labs
Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.
Interactive Lab¶
MZCacheView Interactive Lab
Practise a guided MZCacheView workflow in a safe browser simulation with immediate feedback.
- 1Source
- 2Configure
- 3Review
- 4Explain
Choose the authorised, traceable source
The case question is bounded. Select the item that preserves scope and provenance.
Select a source to continue.
URL, title or filename
Do this nowEnter the requested value, then select Search profile. Open the guided hint if you need an exact example.
Guided hintFilter for the filename in the case brief.
Enter the acquisition command, then run the simulation.
Identify the result that answers the case question
Inspect the host, output, expected size and integrity fields. A completed tool run is not automatically a finding.
| Time | Type | URL | State |
|---|---|---|---|
| 10:12:41Z | Download | invoice-review.zip | Complete |
| Background activity outside the case window | |||
Select the row that should be preserved for analysis.
Choose the conclusion supported by the result
Separate the acquired evidence from interpretation and state the next analytical step.
Full Lab¶
MZCacheView Full Lab
Hands-on DFIR proof of concept
Prepare it. Examine it. Explain it.
Use MZCacheView to inspect Firefox cache entries and export one relevant resource safely, retain the evidence trail and write a bounded finding another analyst can review.
Safety boundary
Use copied profiles. Do not open recovered links or downloads on the analyst workstation.
a copied training browser profile or supplied browser artefact set
a browser observation linked to profile, source artefact, time context, and corroborating evidence
Recommended first
Beginner Core Lab¶
Complete one bounded MZCacheView workflow using the documented source, settings and expected result.
Optional extension
Add a comparison¶
After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.
Full Lab scenario¶
You are the first analyst reviewing a bounded training case. Your task is to inspect Firefox cache entries and export one relevant resource safely. The result must be understandable to a second analyst who did not watch you perform the work.
01
Activity 1: Prepare the environment¶
- Record the case question, authority and the identity of the isolated training system or evidence source.
- Record the MZCacheView version, provenance, system time and time zone.
- Identify the original material, working location and separate output destination. Confirm that there is enough free space.
- Take or verify a recoverable baseline before changing the training system.
02
Activity 2: Complete the focused task¶
- Restate the investigation question and select only the settings or commands required to inspect Firefox cache entries and export one relevant resource safely.
- Follow the preserved MZCacheView guide and record any necessary difference in paths, labels or version-specific behaviour.
- Record start and finish times, relevant settings, completion status, warnings and errors.
- Preserve the returned output and keep it attributable to its source and collection context.
03
Activity 3: Review and report¶
- Work from an identified copy and confirm a browser observation linked to profile, source artefact, time context, and corroborating evidence.
- Separate direct tool observations from analyst interpretation. Record missing fields, unavailable material and alternative explanations.
- Preserve relevant integrity information, settings or commands and the evidence needed for another analyst to reproduce the result.
- Write a bounded conclusion with observation, interpretation, confidence and limitations, then clean up the disposable environment.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.
-
Core completion¶
Required to demonstrate a safe, attributable workflow.
-
Good analyst practice¶
Supplementary records that improve reproducibility and review quality.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.