How To Use SIFT Workstation
To use SIFT Workstation effectively, you need to install it as a virtual machine, then leverage its pre-installed tools like The Sleuth Kit for file system analysis, Volatility for memory forensics, and Wireshark for network traffic investigation. This guide walks you through the entire process, from setup to advanced analysis, with verified best practices and troubleshooting tips to ensure your investigations are accurate and forensically sound.
What is the SIFT Workstation?
The SANS Investigative Forensic Toolkit (SIFT) Workstation is a free, open-source Linux distribution, based on Ubuntu, specifically designed for digital forensics and incident response. It comes pre-loaded with hundreds of specialized tools, making it a comprehensive platform for analyzing digital evidence across multiple domains, including file systems, memory dumps, and network traffic. Whether you're a professional investigator or a student, SIFT provides a ready-to-use environment that eliminates the need to manually compile and configure forensic tools.
The distribution is maintained by the SANS Institute and benefits from community contributions, ensuring it stays current with the latest forensic techniques. Its open-source nature means you can audit the code, customize the environment, and trust that your analysis is built on transparent, verifiable tools. For incident responders, SIFT offers a consistent, repeatable platform that can be deployed quickly in critical situations, while for educators, it serves as an excellent teaching tool for demonstrating real-world forensic methodologies.
How to install SIFT Workstation for optimal performance
Installing SIFT Workstation is straightforward, but proper resource allocation is critical for handling large evidence files and running memory-intensive tools. The recommended approach is to deploy it as a virtual machine (VM) rather than on physical hardware, as this provides better snapshot capabilities, easier rollback, and more flexible resource management.
Step 1: Download the SIFT Workstation image
Visit the official SANS SIFT download page and choose the pre-built VM image (available in OVA format for VMware or VirtualBox). This image is optimized for forensic work and includes all necessary tools pre-installed. Alternatively, you can download the ISO if you prefer to install on physical hardware, but the VM route is strongly recommended for most users.
Step 2: Allocate system resources
For optimal performance, allocate substantial disk space (preferably SSD/NVMe storage) to the VM. The VM should also have at least 2-4 processor cores to handle parallel processing tasks efficiently.
Step 3: Create a separate evidence volume
One of the most important configuration steps is to use a separate volume for evidence storage. This means creating a second virtual disk or mounted partition specifically for storing case files, disk images, and analysis outputs. This separation ensures that your operating system files and your evidence files don't compete for the same storage space, which can cause performance degradation and complicates chain-of-custody documentation. Mount this evidence volume at a dedicated path like /evidence and always store your case files there.
Step 4: Import and configure the VM
Import the downloaded OVA file into your hypervisor. For VMware, use File → Open and select the OVA; for VirtualBox, use File → Import Appliance. Once imported, adjust the VM settings to match your resource allocation. Boot the VM and complete the initial setup wizard, which will prompt you to create a user account and set a password. After booting to the desktop, update the system using the terminal: sudo apt update && sudo apt upgrade -y to ensure you have the latest security patches and tool updates.
How to use SIFT Workstation to analyze file systems
File system analysis is the foundation of most digital investigations, and SIFT provides The Sleuth Kit (TSK) as its primary toolset. TSK is a collection of open-source command-line tools that allow you to examine disk images without modifying them, which is crucial for maintaining evidence integrity.
Mounting a disk image read-only
Before you can analyze a disk image, you must mount it read-only to prevent any accidental modifications. Use the following command to mount a raw disk image (e.g., a .dd or .raw file):
sudo mount -o loop,ro /path/to/evidence.dd /mnt/evidence
For images with multiple partitions, use losetup to associate the image with a loop device, then mount individual partitions. Alternatively, use kpartx to map all partitions: sudo kpartx -a -v /path/to/evidence.dd followed by mounting the mapped devices. Always verify the mount is read-only with mount | grep /mnt/evidence before proceeding.
Listing files with fls
The fls command lists files and directories within a file system image. This is your primary tool for navigating the directory structure:
fls -r /dev/loop0p1
The -r flag recursively lists all directories. You'll see output with inode numbers, file types, and names. To list deleted files, add the -d flag: fls -rd /dev/loop0p1. This shows files that have been deleted but may still be recoverable.
Recovering deleted files with icat
When you identify a deleted file's inode number from fls, use icat to extract its contents. For example, if inode 4567 is a deleted JPEG, run:
icat /dev/loop0p1 4567 > /evidence/recovered.jpg
This command reads the data blocks associated with that inode and writes them to a new file. Always save recovered files to your separate evidence volume, never to the mounted read-only image.
Building a timeline with mactime
Timeline analysis helps you reconstruct events by ordering file activity chronologically. Use fls to create a body file, then process it with mactime:
fls -r -m / /dev/loop0p1 > /evidence/body.txt
mactime -b /evidence/body.txt > /evidence/timeline.csv
The -m flag with / sets the mount point for path construction. The resulting CSV file contains timestamps for file modification, access, and creation, allowing you to spot suspicious activity patterns.
How to use SIFT Workstation for memory forensics
Memory analysis reveals what was running on a system at the time of acquisition, including processes, network connections, and potentially malicious code. Volatility is the industry-standard tool for this task and comes pre-installed on SIFT.
Identifying the memory profile
First, determine the operating system and version of your memory dump using the imageinfo plugin:
volatility -f /evidence/memory.raw imageinfo
This command analyzes the dump's structure and suggests a profile (e.g., Win10x64_19041). Note the suggested profile; you'll need it for all subsequent commands. If imageinfo is slow, you can use kdbgscan or kpcrscan for faster, more targeted identification.
Analyzing processes with pslist
Once you have the profile, list running processes:
volatility -f /evidence/memory.raw --profile=Win10x64_19041 pslist
This shows active processes with their PIDs, parent PIDs, and start times. For a more thorough analysis, use pstree to visualize parent-child relationships, or psscan to find hidden or terminated processes that may have been unlinked from the active list.
Examining network connections with netscan
To see network connections that were active at the time of acquisition, use:
volatility -f /evidence/memory.raw --profile=Win10x64_19041 netscan
This plugin scans for both TCP and UDP connections, showing local and remote addresses, ports, and connection states. Suspicious connections to unknown external IPs or unusual ports can indicate command-and-control communication or data exfiltration.
Extracting additional artifacts
Volatility includes hundreds of plugins for specific tasks. For example, malfind finds injected code in processes, dumpfiles extracts files from memory, and hashdump retrieves password hashes. Always start with pslist and netscan to establish a baseline, then use targeted plugins based on your investigation's needs.
How to analyze network traffic with SIFT Workstation
Network forensics allows you to examine communication patterns, identify malicious activity, and extract evidence from packet captures. Wireshark is the primary tool for this analysis on SIFT, offering both GUI and command-line interfaces.
Capturing and filtering traffic
To capture live traffic, launch Wireshark from the terminal (sudo wireshark) and select the appropriate network interface. For analysis of existing captures, open a .pcap file directly. Use Wireshark's display filters to narrow your focus. For example, to see only HTTP traffic, type http in the filter bar; to filter by IP, use ip.addr == 192.168.1.100.
For command-line filtering, use tshark (Wireshark's terminal version):
tshark -r capture.pcap -Y "http.request"
This extracts only HTTP request packets. You can combine filters with logical operators (and, or, not) to isolate specific traffic patterns, such as ip.addr == 10.0.0.5 and tcp.port == 443.
Identifying suspicious communication patterns
Look for anomalies such as repeated connections to a single IP on unusual ports, large data transfers during off-hours, or DNS queries for known malicious domains. Use Wireshark's Statistics menu (or tshark -z options) to generate protocol hierarchies and conversation lists. For example, tshark -r capture.pcap -z io,phs shows protocol statistics, while tshark -r capture.pcap -z conv,tcp lists all TCP conversations, helping you spot unusual endpoints.
Extracting transferred files
Wireshark can reassemble and extract files transferred over protocols like HTTP, SMB, or FTP. In the GUI, right-click on a packet and select "Follow" → "TCP Stream" to see the full conversation. For automatic extraction, use:
tshark -r capture.pcap --export-objects http,/evidence/extracted_http/
This extracts all HTTP objects (files, images, scripts) to the specified directory. For other protocols, use the appropriate export function or manually reassemble streams using tcpflow, which reconstructs TCP sessions into files based on connection tuples.
Essential forensic principles and troubleshooting
Adhering to forensic best practices ensures your findings are admissible in court and your analysis remains repeatable. The following principles and troubleshooting tips will help you avoid common pitfalls and maintain the integrity of your investigations.
Maintaining evidence integrity
When performing forensic analysis, it is crucial to maintain the integrity of digital evidence by always working with read-only access to source images and utilizing working copies to prevent unintentional changes. This means never mounting the original evidence directly; instead, create a copy using dcfldd or dd and work on that copy.
Verifying tool availability and versions
Before running any command, always confirm the existence of a command using command -v, review its local help documentation, and record the version to ensure accurate and repeatable investigations. For example:
command -v fls && fls -V
This checks that fls is installed and displays its version. Record this information in your case notes, along with the SIFT version (cat /etc/os-release) and any tool-specific versions you rely on. This documentation is essential for reproducibility and for defending your methodology in legal proceedings.
Common troubleshooting tips
If a tool fails to run, first check for missing dependencies or permission issues. Many SIFT tools require root privileges; use sudo where necessary. If a command returns "command not found," the tool may not be in your PATH, check /usr/bin or /usr/local/bin. For memory analysis, if imageinfo fails, try specifying the profile manually or use volatility --info to list all available profiles and match against known OS versions.
Performance issues are often due to insufficient resources. If SIFT runs slowly, close unnecessary applications, increase VM memory allocation, or move your evidence volume to faster storage (NVMe). If you encounter errors related to file system mounting, verify the image is not corrupted with fsck (on a copy, never the original) and ensure you have the correct loop device mappings.
Finally, if you're stuck, consult the SIFT Workstation documentation and the SANS community forums. These resources contain solutions to common problems and guidance on advanced techniques. The SIFT Workstation is backed by an active user community, and searching for error messages often yields immediate solutions. Remember to document every command you run and every output you receive, as this creates a transparent audit trail that strengthens your investigation's credibility.

















