Install and open Hibernation Recon¶
Use a disposable analyst VM and record the download URL, retrieval time, version, filename and vendor-published integrity information before extraction.
Download the package¶
Go to the Arsenal Recon download page and download Hibernation Recon.
This opens a download link. Select Download and retain the original archive.
Stage and verify¶
- Calculate SHA-256 for the downloaded archive and record the result.
- Extract the archive beneath
C:\Toolswithout changing its contents. - Retain the supplied readme, licence and release information.
- Record the executable filename and architecture before launch.
The original SUSA procedure extracts the package to the versioned Hibernation
Recon folder, renames that folder to Hibernation Recon, and double-clicks the
executable to verify that it starts without an error.
Choose the authorised mode¶
Run Hibernation Recon again. The original procedure selects OK to continue in Free Mode. Record the displayed version and selected mode because available recovery features differ between Free and Professional modes.
Current platform requirements
Requirements can change with releases. Consult the bundled readme and the vendor FAQ rather than assuming that an older .NET runtime or executable is appropriate for the evidence workstation.
Installation record¶
Source URL, download time, filename, version and archive SHA-256.
Path, architecture, executable hash and administrator context.
Free or Professional, licence state, warnings and any network access used for activation.




