There are three different ways to start the forensic virtual machine (forensicVM). These methods provide flexibility depending on your access level and location within the system interface:
Another option to start the forensicVM is from the web remote screen. This method may be preferred if you are working remotely or through a particular service interface:
Navigate to the web remote screen.
Locate the start button, as shown in the figure below.
Press the start button to initiate the virtual machine.
These three methods ensure that you can initiate the forensicVM from various points in the system.
Special Case: Starting the ForensicVM in Link Mode
Precautions and Considerations:
When a forensic image is converted to a forensic virtual machine using the “Virtualize b) Link to VM” option, it can only be started via the Autopsy Plugin. Ensure that you adhere to the following precautions to guarantee a smooth operation of the virtual machine:
Warning
Only initiate the linked forensicVM through the Autopsy Plugin. Avoid using the forensicVM web interface—it will be ineffective.
Utilize a reliable internet connection, such as fiber optics. Any connection disruptions could lead to machine disk timeouts, and potentially the virtual machine encountering a “blue screen of death.”
Maintain the command line window in an open state. This window must remain open at all times. To power off or stop the forensicVM, use the “Stop” or “Shutdown” options in the Autopsy Plugin. This method ensures the prevention of lingering mount points on your computer, which could cause issues.
Steps to Start, Stop, or Shutdown:
Activate ForensicVM in the Main Plugin Interface:
To initiate the VM, click the “Start” button.
Fig. 64 The “Start” button in the main plugin interface.
Following this action, a popup will inform you that the machine has launched in “snap” or link mode.
Next, a command line window will manifest. While you should minimize it, it’s crucial not to close it. If you need to shut down the machine, kindly adhere to the subsequent steps to safely halt or power off the forensicVM.
Fig. 66 Command line window – important not to close.
To interact with the machine through its graphical interface, hit the “Open ForensicVM” option.
It’s imperative to note that the solitary and secure method to halt or power off the machine is by utilizing the “Shutdown” or “Stop” buttons available in the Autopsy Plugin.