How To Make Windows10 To A Disposable VM Template

56 views
Skip to first unread message

Zsolt Bicskey

unread,
Apr 29, 2020, 1:59:40 PM4/29/20
to qubes...@googlegroups.com
I have a Window 10 HVM installed. I want to to use it for Malware analysis. Is there any way I can make a disposable VM template?



publickey - letmereadit@protonmail.com - 0xEE010E73.asc
signature.asc

Sven Semmler

unread,
Apr 30, 2020, 3:08:40 PM4/30/20
to Zsolt Bicskey, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Wed, Apr 29, 2020 at 05:59:26PM +0000, 'Zsolt Bicskey' via qubes-users wrote:
> I have a Window 10 HVM installed. I want to to use it for Malware analysis. Is there any way I can make a disposable VM template?

Is it a StandaloneVM or a Template based AppVM?

In case it is the later, have you set the template_for_dispvms property
to true?

/Sven

- --
public key: https://www.svensemmler.org/0x8F541FB6.asc
fingerprint: D7CA F2DB 658D 89BC 08D6 A7AA DA6E 167B 8F54 1FB6

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE18ry22WNibwI1qeq2m4We49UH7YFAl6rIb8ACgkQ2m4We49U
H7aUxxAAtqFZzpgw57oyPPSf1pCko22M2hVp4LG2fVVHe3VOymuqQr1g3ZFAy/++
S+A1YO4fP0oZTxN1goSQSKWKVVhtxXJ6INKMK6IXvDDgYXOTjCmYzR/wsrYUSfW4
ginjef1mKLkkcKbIzhW31sNbRljxmJjKIOkFGQLwI3U3H8Xq/be6D5vXnQ76x7hu
8WKeVxB6UvBOeHRg046vjO2TI7VfDRxAWYzU3G2jgerqQefMFFN4TBt1+mh9gl3y
MMe3mTS/TMR8K+wSWurcsa3PkFI25uk6jf3p3D2dduCUGOCN1fwieUkpzf86UW0H
hvP9ERmaFnFUqagv6GoEvFTTjbt8Wx6vg6qf9FBUkk8YBeZ+lEMEcLY6uyEn+cxW
60yJWAD3mHOJaCUqOmC/P6AxNhpmPDM+v/BIF4DjwjXQcTw+qyp3fsGqLPKtACz3
KWcx4pY54h5iojpvmz2mmCNlzTX6svczAIR193BYk3ZU+ZjzfJfVqWnAcpshPJoF
vsWrhtf64encSErfYhZmQYEfqCC19O23BOZubMqyZgseKFY20ZynihKbSF1KDRnA
iJ/Rj77UmewYaZ0n6rXeT3Fp4p80OZdwBONQ0LW0N5niEAcWU3A8Isp3H+llnJD0
shLcq79CF/V0TFlciZwoSvUu4WoZSY3PSL6n1YcFzlwedl5sVm4=
=relF
-----END PGP SIGNATURE-----

Sven Semmler

unread,
Apr 30, 2020, 6:37:06 PM4/30/20
to Zsolt Bicskey, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Thu, Apr 30, 2020 at 07:22:32PM +0000, Zsolt Bicskey wrote:
> It is a standalone VM installed from an ISO. That's only way I knew how to install a Windows VM. Is there any other way?

There are many ways. Searching the mailing list archive will illuminate
that for you.

You might be in luck if you installed the windows qube without QWT and
have not moved the profile folder to the private volume (QWT does that
automatically, otherwise you'd know you've done it). In that case you
could simply run:

qvm-clone --class TemplateVM standalone-win template-win
qvm-create --template template-win --label red dvm-win

Now if you run dvm-win is is effectively a dispvm since everytime you
restart the root volume get's restored from the TemplateVM.

Would that work for you?

Also: please use the "Reply all" function to make sure your emails are
posted to the list.

/Sven

- --
public key: https://www.svensemmler.org/0x8F541FB6.asc
fingerprint: D7CA F2DB 658D 89BC 08D6 A7AA DA6E 167B 8F54 1FB6

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE18ry22WNibwI1qeq2m4We49UH7YFAl6rUwYACgkQ2m4We49U
H7bFeRAAvfI48ZsZBMynyy0s9fxygckl+/4obyAwdomOUDmUEG3ROKNFDxfLkDiO
fNUxJppWhMEWeBoCOxKnD8AZsb5gRxJ8vXHXrB+nyYOPu5KgJ6gncnnXFDB2t+se
gFxoKeCbmxc7U0Z+/WoibKZZoK8FXtAfpL20jzzY1YZrrnfL+Ff9YqmKj7T9FEZL
ruenKZr9sPeUOj62PWH3j6BE2MxHlbn9ojZ1A5xt0oYstTXIIrsda8cHnVhnOqL5
LsLK195mN2PGxr3p+X6GW+p2ykvjyxKPgKi8YzysuDTrUywPyqmSBJKI/ADNTwEv
CwWaxTnJCNB/9/m0zReI/9vt6LKMDB/s2YgX4a77UBKgDInAVo4jLtIRGsvkibik
2z+8aKUthrYhmNR10Uerqf4k2Tw4+vJOuEX+fvmLStTrmJNWpKIo9+CwAJMmW+ei
SMPVp8VZ7X6DlBwbhxKfaikla69MJxt9r0GtibHLFb0c7DOb/46KXvIJyIKuAYcx
H+pXnfEpPEzzpH9yqkYfYmOdKVUSk6hRTi7r5d/2DD3HmhAHKFU1+51t+jM5w5FK
NeJ9F+CxOU0OKMmo6rIJ5oUE189jkQHzmq2f/hTYBEAJ6aN2jvpEa9dLLUeg1Pkh
t1dV4NEzmnv2CgfveWi/uTmBnExcjhDgfI6t+9beaPc3Zbt5BNo=
=INGl
-----END PGP SIGNATURE-----

Zsolt Bicskey

unread,
Apr 30, 2020, 7:02:27 PM4/30/20
to Sven Semmler, qubes...@googlegroups.com
This is it! Thank you very much. This is incredible.





‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Thursday, April 30, 2020 6:36 PM, Sven Semmler <sv...@svensemmler.org> wrote:

> On Thu, Apr 30, 2020 at 07:22:32PM +0000, Zsolt Bicskey wrote:
>

> > It is a standalone VM installed from an ISO. That's only way I knew how to install a Windows VM. Is there any other way?
>

> There are many ways. Searching the mailing list archive will illuminate
> that for you.
>

> You might be in luck if you installed the windows qube without QWT and
> have not moved the profile folder to the private volume (QWT does that
> automatically, otherwise you'd know you've done it). In that case you
> could simply run:
>

> qvm-clone --class TemplateVM standalone-win template-win
> qvm-create --template template-win --label red dvm-win
>

> Now if you run dvm-win is is effectively a dispvm since everytime you
> restart the root volume get's restored from the TemplateVM.
>

> Would that work for you?
>

> Also: please use the "Reply all" function to make sure your emails are
> posted to the list.
>

> /Sven
>

> ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
publickey - letmereadit@protonmail.com - 0xEE010E73.asc
signature.asc
Reply all
Reply to author
Forward
0 new messages