Diagram of four virtual machines connected to an ESXi host server with shared resources

Situational Awareness – OSINT and Awareness

In the field we never reused a compromised radio or a dirty weapon. The same rule applies to digital investigations. Once you start browsing, downloading, or analyzing, that environment carries residual data. A virtual machine (VM) solves this. It runs a complete operating system inside your host computer, completely isolated. When the work is finished you delete it, restore a clean snapshot, or clone a fresh copy. No leftover cookies, no persistent malware, no cross-contamination between targets.

Linux is the preferred guest system for most OSINT work. It is lightweight, free, runs on almost any hardware, and the majority of malicious code still targets Windows. A properly built Linux VM lets you visit high-risk sites, test tools, and collect data without exposing your personal machine.

The rest of this article walks through the exact steps to build and maintain these environments on Windows/Linux hosts (using VirtualBox) and on Apple Silicon or Intel Macs (using UTM). Follow the procedures once, verify them, and treat the finished VM as operational equipment.

Virtual Machines

A virtual machine is a complete computer running inside another computer. The host operating system stays untouched. Each VM is independent—you can run multiple at the same time, clone them in minutes, or destroy them without affecting the host. This isolation is the core security benefit for OSINT and preparedness work.

Free tools are sufficient. On Windows and Linux hosts use VirtualBox. On modern Apple machines use UTM. Paid options exist but are unnecessary for this mission.

Windows & Linux Host Virtual Machines

VirtualBox Download the latest VirtualBox from the official site and install it with default settings. Also download the matching Extension Pack and install it. On a Linux host the commands are: sudo apt update sudo apt install virtualbox virtualbox-ext-pack -y

Ubuntu Linux Download the current Ubuntu 22.04 LTS Desktop ISO (64-bit). Create a new VirtualBox VM named something operational such as “OSINT-Original.” Allocate 50 % of your system RAM and 50 % of available CPU cores. Set the hard disk to VDI, dynamically allocated, and size it to at least 50 GB (100 GB is safer if space allows). Attach the Ubuntu ISO as the optical drive and start the VM.

During installation choose “Normal Installation,” erase the disk, set a simple local username and password (example: osint / osint), and skip the online account. After first boot install Guest Additions: Devices → Insert Guest Additions CD Image → Run. Reboot when finished. This enables proper display scaling, shared folders, and clipboard.

Snapshots After the base system is clean and Guest Additions are installed, shut the VM down. In VirtualBox take a snapshot named “Original.” This becomes your known-good restore point. After any investigation or update, either restore the Original snapshot or create a new clean one. Never continue working from a contaminated state.

VM Exports and Clones To preserve evidence or move a clean environment, shut the VM down and use File → Export. For daily work, right-click the original VM and choose Clone. Give the clone a new name. Work only inside the clone; leave the original untouched. This keeps a pristine master ready for the next task.

Issues VT-x / AMD-V must be enabled in the host BIOS/UEFI. If the VM fails to start with a virtualization error, reboot into firmware settings, enable the virtualization option, and save. On some Windows 10/11 systems Hyper-V can conflict—disable it in Windows Features if VirtualBox cannot start.

Display problems are usually fixed by installing Guest Additions and setting the VM display to use the maximum available video memory and enabling 3D acceleration if needed.

The following only applies to VirtualBox VMs (Size & Shrinking) Over time the virtual disk grows. To reclaim space:

  1. Fill free space inside the Ubuntu VM with zeros: dd if=/dev/zero of=zerofillfile bs=1M (then delete the file).
  2. Shut the VM down.
  3. On the host run: VBoxManage modifymedium disk “path-to-vdi” –compact

This returns unused space to the host without harming the VM.

Apple Host Virtual Machines

UTM On macOS install UTM via Homebrew: brew install –cask utm UTM is free, open-source, and works on both Intel and Apple Silicon Macs. It is the recommended tool for modern Macs.

Virtualize vs Emulate

  • Virtualize – Uses the host CPU directly. Fast. Available only when the guest architecture matches the host (ARM guest on Apple Silicon, x86 guest on Intel).
  • Emulate – Translates instructions. Slower but lets you run x86 Ubuntu on Apple Silicon if needed. Prefer Virtualize whenever possible.

Ubuntu 22.04 LTS Desktop Only (Intel or when matching architecture) Download the standard Ubuntu 22.04 LTS Desktop ISO. In UTM create a new Virtual Machine, choose Virtualize, select Linux, and point to the ISO. Allocate roughly half your RAM and half your performance cores. Continue through the Ubuntu installer exactly as on VirtualBox (local account, erase disk, no online account).

Ubuntu 22.04 ARM Daily Desktop Only (Apple Silicon) For native speed on M1/M2/M3 Macs download the ARM64 daily build of Ubuntu Desktop. Create the VM with Virtualize selected. The installation steps are identical.

All Ubuntu Installations After first boot, install the spice guest tools if prompted for better integration: sudo apt update sudo apt install spice-vdagent spice-webdavd Set a solid-color desktop background and disable unnecessary animations for a cleaner operational look.

Ubuntu Customization

  • Disable crash reporting and telemetry: sudo apt purge -y apport apport-symptoms popularity-contest ubuntu-report whoopsie sudo apt autoremove -y
  • Turn off notifications, blank screen, and automatic suspend in Settings.
  • Add useful tools to the Dock as needed.
  • For shared folders: in UTM settings enable a shared directory, then inside Ubuntu open the Spice client or Files → Other Locations to access it.

USB Connection UTM supports USB passthrough. Plug the device into the host, then in the running VM window select the USB device from the menu. It appears inside the guest for data transfer or tool use.

Snapshots UTM provides snapshot capability. After the base system is configured, take a snapshot named “Original.” Restore it after every investigation or before major changes. This is faster and cleaner than rebuilding.

VM Exports and Clones Shut the VM down. Use the Share or Export option in UTM to create a portable copy. For daily work, clone the original VM and operate only inside the clone. Keep the master pristine.

Issues If the VM window is unresponsive or display scaling is wrong, adjust the display settings inside UTM and ensure the spice agent is installed. Shared folder access sometimes requires a reboot of the guest after enabling the share.

Virtual Machine Size & Shrinking UTM handles disk growth more cleanly than older VirtualBox setups. If space becomes an issue, shut the VM down and use the reclaim or compact option in the UTM settings for that virtual drive. Avoid unnecessary snapshots that accumulate large delta files.

macOS Virtual Machines You can also run a clean macOS guest inside UTM on Apple Silicon for specific testing, but for pure OSINT collection the Linux guests above remain the primary recommendation. Keep any macOS guest equally isolated and snapshot-protected.

Summary

  • Windows or Linux host → VirtualBox + Ubuntu 22.04 LTS
  • Apple Silicon host → UTM + Ubuntu ARM (Virtualize)
  • Always start from a clean “Original” snapshot or clone
  • Never conduct investigations on the host operating system
  • Delete or restore the working VM after each major task

These disposable environments give veterans a repeatable, auditable, and secure workspace for OSINT and preparedness research. Build the master once, verify it, and then operate with confidence that every investigation starts clean.


Leave a Reply

Discover more from AnAmericanVeteran.com

Subscribe now to keep reading and get access to the full archive.

Continue reading