Skip to content

XstReader

What XstReader does

Guided SUSA tool journey

XstReader supports email forensics. In this guide, you will use it to inspect a training mail store and export a relevant message or attachment safely. The procedure and screenshots provide the practical reference; the surrounding context explains what to record and how to judge the result.

Tool guide at a glance

Investigation task

Inspect a training mail store and export a relevant message or attachment safely.

Starting material

A copied training mail store or message set with account and acquisition context.

Successful outcome

A message finding supported by identifiers, headers, mailbox context, and safely handled attachments.

Evidence and safety

Do not open recovered attachments or links on SUSA. Preserve the source store and exported-message provenance. Record the input identifier, tool version, relevant commands or settings, time and time zone, output location, and any errors or limitations as you work.

Choose your journey

How the labs complement this guide

The Interactive Lab is a safe browser simulation for practising the workflow and validation logic. The Full Lab is an independent exercise for an isolated, authorised environment. Confirm the installed tool version and expected output before relying on either exercise in a real case.

Accessing XstReader in SUSA

XstReader is an open source viewer for Microsoft Outlook’s .ost and .pst files.

Download the forked version of XstReader. Download the XstReader.App.(version).zip.

Screenshot: Download the forked version of XstReader. Download the XstReader.App.(version).zip

Extract the contents of the zip archive to C:\Tools folder. This will automatically create the C:\Tools\XstReader.App.2.1.1 and extract the contents.

Rename the XstReader.App to XstReader and double-click to launch the application.

Screenshot: Rename the XstReader.App to XstReader and double-click to launch the application

If prompted to install .NET version 6.0.0, click Yes to proceed.

Screenshot: If prompted to install .NET version 6.0.0, click Yes to proceed

This will download .NET Desktop Runtime from the internet. Double-click the executable and click Install.

Screenshot: This will download .NET Desktop Runtime from the internet. Double-click the executable and click Install

After installation is complete, click Close.

Screenshot: After installation is complete, click Close

Open XstReader again and confirm that the application starts without an error.

Screenshot: Open XstReader again and confirm that the application starts without an error