Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

WinFE has some street cred with the Scientific Working Group on Digital Evidence

By Brett Shavers
February 20, 2014
2

Cool.  WinFE is mentioned in a Scientific Working Group on Digital Evidence document.

SWGDE UEFI and its Effect on Digital Forensics Imaging
 
swgdehttps://www.swgde.org/documents/Current%20Documents/2014-02-06%20SWGDE%20UEFI%20Effect%20on%20Digital%20Imaging%20V1

Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
Previous

No surprise. XWF does something other tools don’t

Next

Hacking Exposed – Daily Blog #242, How to build WinFE to add to the Multiboot thumbdrive

2 Comments
  1. marc says:
    February 20, 2014 at 10:17

    well, not exactly IMHO – it is only mentioned as a tool for “Booting from forensic distribution media (e.g., Raptor, Windows FE) […]”. But when it comes to a recommendation, the text only mentions Windows PE in section 5 (“Boot to a UEFI compatible boot environment, which MAY include: *Windows PE *Windows To Go”). While possibly just a mistyping it gives some dubious impression.

    Reply
  2. Brett Shavers says:
    February 20, 2014 at 10:31

    Yes, not detailed in the doc, but between emails about WinFE when the doc was being written, it’s one of the boot methods recommended. The point mainly being to give credibility to a forensic tool as valid (along with the other tools mentioned in the paper as well). I mention the paper only because I still get emails arguing WinFE not being an effective and ‘accepted’ method (I’m not sure why I get asked since I didn’t create WinFE…).

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • X
  • LinkedIn
  • Bluesky
  • Instagram
  • Mastodon
  • FACT Attribution Framework
  • https://www.dfir.training
  • https://winfe.wordpress.com
  • https://xwaysforensics.wordpress.com

My recent interview on a really good DFIR podcast (Parsing the Truth).

  • X
  • LinkedIn
  • Instagram
  • Bluesky
  • Facebook
  • Mastodon
  • YouTube
Copyright 2026 — Brett's Ramblings. All rights reserved.