Skip to content

Arsenal Image Mounter Hands-on Labs

Choose the browser simulation for coached read-only mounting practice, or use the Full Lab with an isolated Windows VM and a disposable training image.

Hands-on image mounting

Verify it. Mount it. Trace it.

Present a verified image read-only, identify its volumes, record one bounded observation and remove the mount cleanly.

⏱ Setup: 20–30 min · Exercise: 35–50 min◆ Guided beginner✓ Evidence required

Interactive Lab

Full Lab

Isolated Windows VM · Setup: 20–30 min · Exercise: 35–50 min

Arsenal Image Mounter Full Lab

Administrator access and training image required

Use a disposable, authorised training environment

Use only a supplied training image or verified working copy. Never practise writable mounting on original evidence. Snapshot the analysis VM and keep exported material on separate controlled storage.

Before you begin

You need: an isolated Windows VM, administrator access, installed AIM, one documented training VMDK/E01 image and separate export storage.

Case question

Can the verified image be presented read-only and does its Windows volume contain the expected Users directory without changing the working image?

Objective

For case SUSA-IMG-021, mount the verified training image read-only, identify the exposed Windows volume, record the presence or absence of Users, unmount cleanly and show that the working-image hash still matches.

01

Activity 1: Establish the working basis

  1. Record authority, case question, image filename, format, byte size and source.
  2. Calculate SHA-256 for the protected image and verified working copy; confirm they match.
  3. Record AIM version, workstation time and export destination.
  4. Explain why read-only disk-device mode answers the question with lower risk than a writable mode.
Milestone 1Working basis verifiedImage identity, integrity, authority and output boundaries are recorded.

02

Activity 2: Mount and inspect

  1. Launch AIM as administrator and select Mount disk image.
  2. Select the verified working image and choose Disk device, read only.
  3. Record sector size, optional settings, mount time and assigned drive letters.
  4. Open the Windows volume and determine whether Users is present. Do not open unrelated personal content.
  5. Export only a harmless case-authorised item if required, to separate controlled storage.
Milestone 2Read-only observation recordedThe mounted volume and bounded observation are attributable to the selected image.

03

Activity 3: Remove and report

  1. Close Explorer and any tool using the mounted drives, then select Remove in AIM.
  2. Confirm all assigned drives disappear and record the unmount time and messages.
  3. Recalculate the working-image SHA-256 and compare it with the pre-mount value.
  4. Write observation, interpretation, confidence and limitations separately.
  5. Record the next analysis step without claiming that directory presence proves user activity.
Milestone 3Mount lifecycle reviewableAnother analyst can reproduce the mount and verify the working image remained unchanged.

Full Lab evidence checklist

  • Core completion

    Required for a defensible read-only mount.

0 of 6 recorded Mark each item after saving the evidence.

Troubleshooting

Symptom First check
AIM does not start Confirm the expected .NET runtime, driver installation, restart and administrator elevation.
Image does not mount Verify format support, working-copy integrity, image path and AIM/driver messages.
No drive letter appears Review partition state, BitLocker status and AIM's listed virtual disk and volumes.
Drive cannot be removed Close Explorer and analysis handles, refresh AIM and preserve any forced-removal message.
Hash changes Stop, protect both copies, review the selected mode and repeat from a newly verified working copy.

Clean up

Confirm no virtual disk remains, protect notes and exports, remove temporary working material when authorised and restore the disposable VM snapshot.