As the tool we are going to use is built-in, there is no need for installation: if you are using Windows, you already have it. So all you need is to mount a forensic image, and you already know how to do this from Chapter 3, Windows Drive Acquisition. As soon as the image is mounted, you are ready to go.