Skip to content

Install and Open Bulk Extractor with Record Carving

The preserved SUSA procedure installs bulk_extractor-1.6.0-dev-rec03 and its Java BEViewer dependency. Use it only in an authorised, isolated Windows lab.

Do not mix product generations

Current upstream bulk_extractor 2.x does not bundle the historical Java BEViewer. These screenshots and paths apply to the supplied rec03 build.

Install the record-carving build

Download the Windows 64-bit installer from the project's release page. Record the filename, source, retrieval date, version, size and published SHA-256 before use.

Screenshot: Download the Windows 64-bit Bulk Extractor with Record Carving installer

Stage it in C:\Tools\Bulk Extractor with Record Carving. Verify the package before responding to SmartScreen; use Run anyway only when the recorded hash, source and organisational policy permit it.

Screenshot: Stage and start the installer after verifying it

Approve User Account Control for the verified installer.

Screenshot: Approve the verified installer through User Account Control

Keep the documented defaults unless the lab build requires a different path, then select Install.

Screenshot: Install the record-carving build

Review installation details and record the displayed application directory, shown here as C:\Program Files\Bulk Extractor 1.6.0-dev-rec03.

Screenshot: Review the installed application location

Satisfy and record the Java dependency

Open BEViewerLauncher from the installed directory. The preserved build may report that Java is missing.

Screenshot: Attempt to open BEViewerLauncher and record any dependency error

Obtain a supported Java runtime from an approved source. Record its vendor, version, architecture, installer filename, source, size and hash.

Screenshot: Download the approved Java desktop runtime

Start the verified Java installer and approve its UAC prompt.

Screenshot: Start the Java installation

Select Install, retaining approved settings.

Screenshot: Install the Java runtime

Close the installer after confirming completion.

Screenshot: Complete the Java installation

Create and verify the SUSA launcher

The supplied journey renames the launcher entry to Bulk Extractor with Record Carving and creates a shortcut in the tool directory. Preserve the actual target path in your notes.

Screenshot: Rename the BEViewerLauncher entry

Create a shortcut pointing to the recorded installed launcher.

Screenshot: Create the SUSA Bulk Extractor with Record Carving shortcut

Keep the descriptive shortcut name and finish creation.

Screenshot: Finish creating the tool shortcut

Open the shortcut with no evidence attached and confirm that BEViewer starts. Record the application and Java versions before proceeding.

Screenshot: Verify that Bulk Extractor Viewer opens without an error

Record Why it matters
rec03 package and SHA-256 Identifies the legacy scanner build and added plugins.
Java vendor, version and architecture Explains viewer compatibility and runtime risk.
Scanner and launcher paths Separates the extraction engine from the viewer entry point.
Installation and verification times Preserves tool provenance before evidence use.