But does it do Mac?

Just to clear up any questions on whether WinFE can ‘do a Mac’, well…it can. And Linux too. And of course it can do Windows as well. As long as the machine can be booted to a WinFE CD or USB, then you can image the hard drive. Actually, you can do a whole lot more than just image it…you can triage it, preview it, search it, or just copy files and folders from it. If the drive is encrypted and you have the key, you can access the drive. And what about VSS (Volume Shadow Service/Copies)….you can access those too, all through WinFE.
I can promise that as soon as you build a WinFE CD or bootable USB, you will regret not having done it months or years earlier (it’s been around since 2008….). And if building a forensic boot OS makes you hesitate at all, there is no need because if you use WinBuilder, it is as simple as pointing and clicking to fully customize your Windows FE CD or bootable USB.
Discover more from Brett's Ramblings
Subscribe to get the latest posts sent to your email.
I think as long, as the suspicious machine has an Intel Architecture, Windows FE will boot. And from there, the Tools will work… Will they? Hm. Many Portable Tools (and also the viewer component of X-Ways Forensics) require special libraries, which are not included in Standard WindowsPE! But, with two clicks in winbuilder, the .NET Framework 2/3 and MS Visual C++ 2005/2008 redistributable libraries are injected automatically. No further configuration… And: it works like a charm!!!
I would post my configuration, but I changed some of the scripts, like also the WinFE forensic section…
Have a nice Day
Andreas
You are completely correct on why WinFE can boot to a Mac (intel Macs anyway). And that is one of the reasons WinFE is such a powerful tool, because you can image (and examine a Mac) with a Windows boot disc/USB and your Windows apps. Niiiiicccceee…