XstReader Hands-on Labs¶
Choose a lab¶
Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.
- Recommended first
- No installation
- Short guided scenario
- Isolated lab required
- Independent decisions
- Evidence or analyst outcome
How to use these labs
Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.
Interactive Lab¶
XstReader Interactive Lab
Practise a guided XstReader workflow in a safe browser simulation with immediate feedback.
- 1Source
- 2Configure
- 3Review
- 4Explain
Choose the authorised, traceable source
The case question is bounded. Select the item that preserves scope and provenance.
Select a source to continue.
Sender, subject or message ID
Do this nowEnter the requested value, then select Search messages. Open the guided hint if you need an exact example.
Guided hintSearch for the subject named in the case brief.
Enter the acquisition command, then run the simulation.
Identify the result that answers the case question
Inspect the host, output, expected size and integrity fields. A completed tool run is not automatically a finding.
| Received | From | Subject | Attachment |
|---|---|---|---|
| 10:11:54Z | accounts@example.test | Invoice review | invoice-review.zip |
| Background activity outside the case window | |||
Select the row that should be preserved for analysis.
Choose the conclusion supported by the result
Separate the acquired evidence from interpretation and state the next analytical step.
Full Lab¶
XstReader Full Lab
Hands-on DFIR proof of concept
Prepare it. Examine it. Explain it.
Use XstReader to inspect a training mail store and export a relevant message or attachment safely, retain the evidence trail and write a bounded finding another analyst can review.
Safety boundary
Do not open recovered attachments or links on SUSA. Preserve the source store and exported-message provenance.
a copied training mail store or message set with account and acquisition context
a message finding supported by identifiers, headers, mailbox context, and safely handled attachments
Recommended first
Beginner Core Lab¶
Complete one bounded XstReader workflow using the documented source, settings and expected result.
Optional extension
Add a comparison¶
After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.
Full Lab scenario¶
You are the first analyst reviewing a bounded training case. Your task is to inspect a training mail store and export a relevant message or attachment safely. The result must be understandable to a second analyst who did not watch you perform the work.
01
Activity 1: Prepare the environment¶
- Record the case question, authority and the identity of the isolated training system or evidence source.
- Record the XstReader version, provenance, system time and time zone.
- Identify the original material, working location and separate output destination. Confirm that there is enough free space.
- Take or verify a recoverable baseline before changing the training system.
02
Activity 2: Complete the focused task¶
- Restate the investigation question and select only the settings or commands required to inspect a training mail store and export a relevant message or attachment safely.
- Follow the preserved XstReader guide and record any necessary difference in paths, labels or version-specific behaviour.
- Record start and finish times, relevant settings, completion status, warnings and errors.
- Preserve the returned output and keep it attributable to its source and collection context.
03
Activity 3: Review and report¶
- Work from an identified copy and confirm a message finding supported by identifiers, headers, mailbox context, and safely handled attachments.
- Separate direct tool observations from analyst interpretation. Record missing fields, unavailable material and alternative explanations.
- Preserve relevant integrity information, settings or commands and the evidence needed for another analyst to reproduce the result.
- Write a bounded conclusion with observation, interpretation, confidence and limitations, then clean up the disposable environment.
Full Lab evidence checklist¶
This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.
-
Core completion¶
Required to demonstrate a safe, attributable workflow.
-
Good analyst practice¶
Supplementary records that improve reproducibility and review quality.
Clean up¶
Protect retained output and case notes, remove harmless training material, clear temporary credentials or access and restore disposable systems to their recorded baseline. Confirm that no test collection remains active.