| 
 (FTK 
Imager Lite: 
Lesson 2){ Create FTK Imager Lite 
ISO with WinISO  } 
 
			
				| Section 0. Background 
				Information |  
	What is the Purpose of this lab?
		In this lab I am showing a student how to 
		create an ISO from FTK Imager Lite.Running FTK Imager from a CD or ISO does 
		not require a forensics investigator to actually install software on the 
		machine that is being analyzed.
What is FTK Imager Lite?
		The Forensic Toolkit Imager (FTK Imager) is 
		a commercial forensic imaging software package distributed by AccessData.The FTK Imager Lite version can be 
		installed and executed from a CD/DVD or USB media.What is WinISO?
		WinISO is a professional CD/DVD/Blu-ray 
		image file utility tool that can: Make disc image files from CD/DVD/Blu-ray 
		Drive. Convert image files between ISO / BIN and other formats. 
		(Including NRG, CCD and MDS image file formats) Extract, edit, rename 
		ISO files directly. 
Pre-Requisite Labs
		
		
		WinISO: Lesson 1: Install WinISO 
	Lab Notes
	
		In this lab we will do the following:
		
			Create a VMware Shared FolderDownload FTK IMAGER LITEBurn FTK IMAGER LITE to an ISO/CDTest FTK IMAGER LITE ISO/CD 
Legal Disclaimer
	
		As a condition of your use of this Web 
		site, you warrant to computersecuritystudent.com that you will not use 
		this Web site for any purpose that is unlawful or 
		that is prohibited by these terms, conditions, and notices.
		In accordance with UCC § 2-316, this 
		product is provided with "no warranties, either express or implied." The 
		information contained is provided "as-is", with "no guarantee of 
		merchantability." In addition, this is a teaching website 
		that does not condone malicious behavior of 
		any kind. Your are on notice, that continuing 
		and/or using this lab outside your "own" test environment
		is considered malicious and is against the law.
		© 2015 No content replication of any 
		kind is allowed without express written permission.    
			
				| Section 1: Log into 
				Damn Vulnerable WXP-SP2 |  
	Start VMware Player
		Instructions
			For Windows 7
				Click Start ButtonSearch for "vmware player"Click VMware PlayerFor Windows XP
				Starts --> Programs --> VMware 
				Player  Start Up Damn Vulnerable WXP-SP2.
		Instructions:
			Click on Damn Vulnerable WXP-SP2Click on Edit virtual machine SettingsNote(FYI):
		For those of you not part of my class, this 
		is a Windows XP machine running SP2.  Edit Virtual Machine Settings
		Instructions:
			Click on Network AdapterClick on the Bridged Radio buttonClick on the OK Button  Play Virtual Machine
		Instructions:
			Click on Damn Vulnerable WXP-SP2Click on Play virtual machine  Logging into Damn Vulnerable WXP-SP2.	 
	
		Instructions: 		
		
			Click on Administrator 
			Password: Supply Password Press <Enter> or Click the Arrow 
			
				| Section 2: Enabled 
				VMware Shared Folder |  
	Virtual Machine Settings...
		Instructions:
			Player --> Manage --> Virtual Machine 
			Settings...  Folder Sharing
		Instructions:
			Click the Options TabClick on Shared FolderClick on the Enabled until power off or 
			suspend radio buttonClick on the Add button  Add Shared Folder Wizard
		Instructions:
			Click on the Next Button  Browse to Shared Folder
		Instructions:
			Click the Browse... button  Browse For Folder
		Instructions:
			Select either your C: Drive or USB: 
			Drive
				Note: 
				In my case, I am using a USB Drive (G:)Click on Make New Folder  Name Folder
		Instructions:
			Name the folder --> "FTK 
			IMAGER LITE ISO"Click the OK Button  Name the Shared Folder
		Instructions:
			Host path:
			G:\FTK 
			IMAGER LITE ISO
				Note: 
				In my case, I am using a USB Drive (G:)Name: FTK IMAGER LITE ISOClick Next  Specify Shared Folder Attributes
		Instructions:
			Check the Enable this share checkboxClick the Finish button  View Shared Folder Results
		Instructions:
			Notice the share that you just createdClick the OK Button   
			
				| Section 3: Verify 
				Network Connectivity |  
	Open a Command Prompt
		Instructions:
			Start --> All Programs --> Accessories 
			--> Command Prompt  Obtain Damn Vulnerable WXP-SP2's IP Address
		Instructions:
			ipconfigNote(FYI):
			In my case, Damn Vulnerable WXP-SP2's IP 
		Address 192.168.1.116.Record your Damn Vulnerable WXP-SP2's 
			IP Address.   
			
				| Section 4: Download 
				FTK IMAGER LITE |  
	Open Firefox
	
		Instructions: 
		
			Start --> All Programs --> Firefox  Navigate to FTK Imager Lite
		Instructions: 
		
			Place the following URL into the 
			address textbox and press enter (See Picture)
				http://www.accessdata.com/support/product-downloadsClick on FTK IMAGER ArrowClick the FTK Imager Lite version 3.1.1 
			Download Link  Save FTK IMAGER LITE
		Instructions:
			Click the Download Now buttonClick the Save File radio buttonClick the OK button  Save Location
		Instructions:
			Navigate to Desktop --> My Documents 
			--> DownloadsClick the Save Button  Go To the Downloads Folder
		Instructions:
			Tools --> Downloads  Open Containing Folder
		Instructions:
			Right Click on Imager_Lite_3.1.1.zipClick Open Containing Folder  Extract Files
		Instructions:
			Right Click on Imager_Lite_3.1.1.zipClick on Extract All...  Extraction Wizard
		Instructions:
			Click the Next Button  Select a Destination
		Instructions:
			Click the Next Button  Extract Completion
		Instructions:
			Click the Finish Button   
			
				| Section 5: Create 
				FTK IMAGER LITE ISO |  
	Start DoISO
		Notes(FYI):
			It is not necessary to use WinISO to 
			burn FTK Imager Lite to an ISO.  You can use Nero, Roxio, or 
			whatever.  However, WinISO is free and good.Instructions:
			Click the Start ButtonAll Programs --> WinISO --> 
			WinISO  Add Directory
		Instructions:
			Click on ActionsClick on Add Directory...  Source Location
		Instructions:
			Navigate to the following location
				C:\Documents and 
				Settings\Administrator\My Documents\Downloads\Imager_Lite_3.1.1Click the OK Button  Set CD-label name
		Instructions:
			Click on ActionsClick on Set CD-label name  Rename Label
		Instructions:
			Rename CD Label to FTK  Save ISO (Part 1)
		Instructions:
			Click FileClick Save as...  Save ISO (Part 2)
		Instructions:
			Navigate to Desktop --> My Documents 
			--> DownloadsFile name: IMAGER_LITE_3.1.1.ISOSave as type: Standard ISO9660 
			Format(*.ISO)Click the Save Button   
			
				| Section 6: Copy ISO 
				to VMware Shared Folder |  
	Create VMware Shared Folders Desktop Shortcut
		Instructions:
			Navigate to
			
			\\vmware-hostRight Click on Shared FoldersSelect Create ShortcutClick the Yes Button  Copy ISO
		Instructions:
			Navigate to the following directory
				C:\Documents and 
				Settings\Administrator\My DocumentsRight click on Imager_Lite_3.1.1.isoSelect Copy  Navigate to the VMware Shared Folders
		Instructions:
			Double Click on the VMware Shared 
			Folders located on the desktop  Paste ISO File
		Instructions:
			Navigate to the FTK IMAGER LITE ISO
				
				\\vmware-host\Shared 
				Folders\FTK IMAGER LITE ISORight Click in the white window pain 
			(See Picture)Select Paste   
			
				| Section 7: Test the 
				ISO/CD Image |  
	Virtual Machine Settings...
		Instructions:
			Click PlayerNavigate to Manage --> Virtual Machine 
			Settings...  Set CD/DVD
		Instructions:
			Highlight CD/DVD (IDE)Check the Connected CheckboxClick the Use ISO image file radio 
			buttonClick the Browse... button and navigate 
			to the ISO location.
				In my case, G:\FTK IMAGER LITE 
				ISO\IMAGER_LITE_3.1.1.ISOClick the OK Button  Start FTK Imager from CD
		Note(FYI):
			
			A Windows Explorer window should have 
			opened up to the D: drive.Instructions:
			Navigate to D:\Imager_List_3.1.1Right Click on FTK Imager.exeSelect Open  Congratuations
		Note(FYI):
			Congratuations you successfully burned 
			FTK IMAGER LITE to a CD and tested it!!!   
	
	Proof of Lab
		Instructions:
			dir D:\ | findstr "FTK"date /techo "Your Name"
				This should be your actual name.e.g., echo "John Gray"
		Proof of Lab 
		Instructions
		
			Press the <Ctrl> and <Alt> key at the 
			same time.Press the <PrtScn> key. Paste into a word document Upload to Moodle
		 | 
    
 
  
		
		
		 |