A little reminder about ‘write protection’
If you try hard enough, you can circumvent just about anything. That includes hard drive write protection, whether you are booting to a Linux forensic OS, WinFE, and sometimes, even when using a physical hardware write protection device. There have also been many instances where write protection methods have unknowingly failed only to be discovered later. This has occurred with several Linux forensics boot systems and at least with one commonly used hardware write protection bridge.
WinFE is not different in that it provides write protection when used appropriately. Perhaps the most important word of advice when touching original evidence with any method of write protection is;
1) don’t mess with the hard drives
2) don’t mess with the hard drives
Particularly in WinFE, as has been discussed before, don’t touch any other disk management tool besides the write protection tool to toggle your drives on/offline.
The safest bet is to not install any disk management tool in your WinFE builds, whether through Winbuilder or any other method. You don’t need them anyway as Colin’s write protect app manages disks much better anyway. As long as you protect the hard drives, you have a great forensic tool, one of many that are in your forensic toolbox.
Discover more from Brett's Ramblings
Subscribe to get the latest posts sent to your email.