Skip to content

Install and open Hibernation Recon

Use a disposable analyst VM and record the download URL, retrieval time, version, filename and vendor-published integrity information before extraction.

Download the package

Go to the Arsenal Recon download page and download Hibernation Recon.

Screenshot: Go to the Arsenal Recon download page and download Hibernation Recon

This opens a download link. Select Download and retain the original archive.

Screenshot: This will open a download link. Click download

Stage and verify

  1. Calculate SHA-256 for the downloaded archive and record the result.
  2. Extract the archive beneath C:\Tools without changing its contents.
  3. Retain the supplied readme, licence and release information.
  4. Record the executable filename and architecture before launch.

The original SUSA procedure extracts the package to the versioned Hibernation Recon folder, renames that folder to Hibernation Recon, and double-clicks the executable to verify that it starts without an error.

Screenshot: Rename HibernationRecon to Hibernation Recon and double-click it to verify that it runs without an error

Choose the authorised mode

Run Hibernation Recon again. The original procedure selects OK to continue in Free Mode. Record the displayed version and selected mode because available recovery features differ between Free and Professional modes.

Screenshot: Run Hibernation Recon again. Click OK to use it in Free Mode

Screenshot: Hibernation Recon open in Free Mode

Current platform requirements

Requirements can change with releases. Consult the bundled readme and the vendor FAQ rather than assuming that an older .NET runtime or executable is appropriate for the evidence workstation.

Installation record

Package

Source URL, download time, filename, version and archive SHA-256.

Executable

Path, architecture, executable hash and administrator context.

Mode

Free or Professional, licence state, warnings and any network access used for activation.