Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

More Windows FE and triage notes (WindowsRipper?)

By Brett Shavers
June 2, 2010
8

Matt Churchhill (http://mattchurchill.net/2010/06/windowsripper/) has been doing some work to supercharge RegRipper.  Take a look at his video and while watching, consider how this can affect your method to triage a computer when booted to WinFE…

[youtube=http://www.youtube.com/watch?v=r4nBUXYGkBw&hl=en_US&fs=1&border=1]


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Tags:

winfe
Author

Brett Shavers

Follow Me
Other Articles
Previous

Windows FE and Triage webinar

Next

Internet Evidence Finder (IEF): interview with Jad Saliba of JADSoftware.com

8 Comments
  1. Rob says:
    June 2, 2010 at 17:30

    Am I correct that once you assign a drive letter to the Volume you are going to be touching the Drive in WinFE?

    Reply
  2. Anonymous says:
    June 2, 2010 at 18:09

    If you set a volume to read only, the disk is written to (offset 0x417). If a disk is set to read only, it is not written to. So as long as you don’t set the volume to read only…

    Reply
  3. Matt C says:
    June 2, 2010 at 18:32

    Thanks for the link, Brett. I hadn’t thought of putting this on WinFE before, but it’s a great idea.

    Reply
  4. Brett Shavers says:
    June 2, 2010 at 18:47

    As fast as RegRipper is, and that it now can be pointed to a mounted drive, plus your addition of adding multiple CLI apps to be called within RegRipper, I can only imagine how quickly a triage can be done on a computer onsite. A bare-bone WinFE disk with only FTK Imager Lite (free) and RegRipper (free) set up as you have worked on means that you can have a lightweight, easy to use, triage (and subsequent imaging tool) at the cost of…a CD Rom…

    Reply
  5. Rob says:
    June 3, 2010 at 04:29

    Not being Fluent in RegRipper… To be “precise” with it..do you need specific plug-in’s? If I just want to see the Recent File List from Windows Media Player (For example…) a plug in would have to target that key to get the output I need… Is it, as it sits “off the shelf” going to report on the entire registry..?

    Reply
  6. Brett Shavers says:
    June 3, 2010 at 08:59

    You can choose the plugins to run, or even write your own plugins if what you are looking for isn’t part of the RegRipper package. You can check out the regripper.net site and forum for better answers from the developer too (Harlan Carvey).

    Reply
  7. ME says:
    June 7, 2019 at 11:08

    NO LINK WORKS FROM YOUR PAGE

    Reply
  8. Brett Shavers says:
    June 7, 2019 at 18:48

    To be fair…this particular blog post is almost 10 years old…

    Reply
Show Comments

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • X
  • LinkedIn
  • Bluesky
  • Instagram
  • Mastodon
  • FACT Attribution Framework
  • https://www.dfir.training
  • https://winfe.wordpress.com
  • https://xwaysforensics.wordpress.com

My recent interview on a really good DFIR podcast (Parsing the Truth).

  • X
  • LinkedIn
  • Instagram
  • Bluesky
  • Facebook
  • Mastodon
  • YouTube
Copyright 2026 — Brett's Ramblings. All rights reserved.