Install and Open Bulk Extractor with Record Carving¶
The preserved SUSA procedure installs bulk_extractor-1.6.0-dev-rec03 and its
Java BEViewer dependency. Use it only in an authorised, isolated Windows lab.
Do not mix product generations
Current upstream bulk_extractor 2.x does not bundle the historical Java BEViewer. These screenshots and paths apply to the supplied rec03 build.
Install the record-carving build¶
Download the Windows 64-bit installer from the project's release page. Record the filename, source, retrieval date, version, size and published SHA-256 before use.
Stage it in C:\Tools\Bulk Extractor with Record Carving. Verify the package
before responding to SmartScreen; use Run anyway only when the recorded
hash, source and organisational policy permit it.
Approve User Account Control for the verified installer.
Keep the documented defaults unless the lab build requires a different path, then select Install.
Review installation details and record the displayed application directory,
shown here as C:\Program Files\Bulk Extractor 1.6.0-dev-rec03.
Satisfy and record the Java dependency¶
Open BEViewerLauncher from the installed directory. The preserved build may
report that Java is missing.
Obtain a supported Java runtime from an approved source. Record its vendor, version, architecture, installer filename, source, size and hash.
Start the verified Java installer and approve its UAC prompt.
Select Install, retaining approved settings.
Close the installer after confirming completion.
Create and verify the SUSA launcher¶
The supplied journey renames the launcher entry to Bulk Extractor with Record Carving and creates a shortcut in the tool directory. Preserve the actual target path in your notes.
Create a shortcut pointing to the recorded installed launcher.
Keep the descriptive shortcut name and finish creation.
Open the shortcut with no evidence attached and confirm that BEViewer starts. Record the application and Java versions before proceeding.
| Record | Why it matters |
|---|---|
| rec03 package and SHA-256 | Identifies the legacy scanner build and added plugins. |
| Java vendor, version and architecture | Explains viewer compatibility and runtime risk. |
| Scanner and launcher paths | Separates the extraction engine from the viewer entry point. |
| Installation and verification times | Preserves tool provenance before evidence use. |













