defencia/knowledge/labs
Forensic lab · Hardware · Virtualization

Labs for Analysis

How to prepare your labs — space, hardware and software requirements — aimed at reusing older hardware rather than buying the latest and greatest.

HardwareVMs

Preparing labs

Have labs ready for in-depth analysis. The author aims to use older, hand-me-down hardware rather than the latest and greatest — that is often the reality.

Forensic lab

A forensic lab needs its own machine — analysing and indexing data is heavy. The constraints are disk read/write speed, RAM and CPU.

Example hardware

ComponentSpec
RAM128 GB
Disks1× 1 TB NVMe (OS) · 2× 2 TB (image analysis + index) · 1× 8 TB (storage/temp)
CPUIntel i9 Extreme or Ryzen Threadripper
GPURTX 3080 / AMD 6900 XT — must support CUDA
Can less do it? Yes — an older i7, 16 GB RAM and a SATA SSD will still let you investigate; it just takes longer. Start there for the first year or two and build knowledge.

Virtualization & ready-made VMs

For both new and old PCs, start with VMware or VirtualBox on a Linux host (Ubuntu / Linux Mint) — Linux leaves more resources for the VMs.