Virtual Live Boot

Boot forensic image files and view electronic evidence in-situ in a forensically sound virtual environment.

Boot both Windows (all versions) and Macintosh computers.

Live Boot gives the investigator a unique perspective into a suspects computer use. It is both an effective investigations tool as well as a means by which compelling evidence can easily be presented to a client, judge or jury.

Common uses of Live Boot are:

  • Bypass or break Windows user-account passwords;
  • Quickly analyze desktop layout and organizational structure;
  • Run installed programs, including proprietary software such as accounting packages;
  • View in situ MRU lists and other forensic artifacts;
  • Revert to Windows Restore Points;
  • and more.

Live Boot utilizes Mount Image Pro (included with a Forensic Explorer purchase) and VMWare or VirtualBox to give fast and reliable access to the virtual environment of forensically imaged computer.

Live Boot Password Recovery:

Virtual Live Boot of a MAC:

Stand Alone Deploy

Create a stand-alone deploy-able Live Boot for non technical investigators to review a suspects computer (see video below). The deployed Live Boot Session requires only Mount Image Pro (MIP) and VirtualBox to be installed.