Host Preparation for Windows Hosts
Log onto a lab workstation as “Sleuth” or a Windows.
Activate the Last Accessed time
time stamp. To do this, Open
. Browse to Local
click the value
and change the data to 0 (false).
Ensure that the operating system has not been configured to encrypt the swap/page file. In
, this setting can be found in the Regi
Make sure the
data for this value is 0.
Ensure that the operating system is not clearing the swap/page file when the system is shut down,
so that it will still be available to
the investigator who images after a graceful shutdown.
Management, and make sure the ClearPageFileAtShutdown value either doesn’t exist or has a
value of 0.
, search for “
local security policy
” in the Windows Start menu. Open “local
settings,” and “Security Options.” Make sure the
lear virtual memory pagefile
option is set to “disable”.
Ensure that the log file for the system’s hostbased firewall
is turned on, and that the log file size
has been increased from the default.
From the Start menu, open Windows Firewall with
Advanced Security. In the center pane, click on the link, “Windows Firewall Properties.” The lab
workstations have the firewall o
just note this; don’t change this. Click on the Public Profile
tab. Next to “logging”, click customize.
Increase the default log file size. Change the “log
dropped packets” and “log successful connections” settings to Yes. Click OK.
Increase the size of
the NTFS. This journal will contain date-time stamps that can be used by a
forensic analyst to investigate file system events even when the primary date-time stamps for file
records have been manipulated.
n a command prompt and type:
fsutil usn quer
The output will display the maximum size of the journal in hexadecimal (e.g., Maximum
Size: 0x0000000002000000”). Enter the hex number into Windows Calculator and switch the
view to Programmer. Select hex, and enter the value. Then switch the
value back to decimal
to see the number of bytes. What is the current size of the NTFS journal?
Increase the size of the NTFS journal by enter the following command:
fsutil usn createjournal m=2147483648 a=1 c:
2147483648 bytes is 2 GB
2 * 1024^3
Verify that the journal size has been increase correctly by running again the command:
fsutil usn queryjournal c: