Arsenal Image Mounter Hands-on Labs¶
Choose the browser simulation for coached read-only mounting practice, or use the Full Lab with an isolated Windows VM and a disposable training image.
Hands-on image mounting
Verify it. Mount it. Trace it.
Present a verified image read-only, identify its volumes, record one bounded observation and remove the mount cleanly.
Interactive Lab¶
Full Lab¶
Arsenal Image Mounter Full Lab
Use a disposable, authorised training environment
Use only a supplied training image or verified working copy. Never practise writable mounting on original evidence. Snapshot the analysis VM and keep exported material on separate controlled storage.
Before you begin
You need: an isolated Windows VM, administrator access, installed AIM, one documented training VMDK/E01 image and separate export storage.
Case question
Can the verified image be presented read-only and does its Windows volume
contain the expected Users directory without changing the working image?
Objective¶
For case SUSA-IMG-021, mount the verified training image read-only, identify
the exposed Windows volume, record the presence or absence of Users, unmount
cleanly and show that the working-image hash still matches.
01
Activity 1: Establish the working basis¶
- Record authority, case question, image filename, format, byte size and source.
- Calculate SHA-256 for the protected image and verified working copy; confirm they match.
- Record AIM version, workstation time and export destination.
- Explain why read-only disk-device mode answers the question with lower risk than a writable mode.
02
Activity 2: Mount and inspect¶
- Launch AIM as administrator and select Mount disk image.
- Select the verified working image and choose Disk device, read only.
- Record sector size, optional settings, mount time and assigned drive letters.
- Open the Windows volume and determine whether
Usersis present. Do not open unrelated personal content. - Export only a harmless case-authorised item if required, to separate controlled storage.
03
Activity 3: Remove and report¶
- Close Explorer and any tool using the mounted drives, then select Remove in AIM.
- Confirm all assigned drives disappear and record the unmount time and messages.
- Recalculate the working-image SHA-256 and compare it with the pre-mount value.
- Write observation, interpretation, confidence and limitations separately.
- Record the next analysis step without claiming that directory presence proves user activity.
Full Lab evidence checklist¶
-
Core completion¶
Required for a defensible read-only mount.
Troubleshooting¶
| Symptom | First check |
|---|---|
| AIM does not start | Confirm the expected .NET runtime, driver installation, restart and administrator elevation. |
| Image does not mount | Verify format support, working-copy integrity, image path and AIM/driver messages. |
| No drive letter appears | Review partition state, BitLocker status and AIM's listed virtual disk and volumes. |
| Drive cannot be removed | Close Explorer and analysis handles, refresh AIM and preserve any forced-removal message. |
| Hash changes | Stop, protect both copies, review the selected mode and repeat from a newly verified working copy. |
Clean up¶
Confirm no virtual disk remains, protect notes and exports, remove temporary working material when authorised and restore the disposable VM snapshot.