Getting a Quick Look at Shadow Volumes
We’ve come to the point where we can conduct a rather complete exam of shadow volumes using dd and E01 image files. Let’s say that we don’t need to do such a complete exam. For example, we’re confident that one, particular folder may contain…
Read MoreWindows 8 and WinFE
Just when you thought WinFE development was done…. Troy Larson (developer of WinFE) has created a cmd script to create a WinFE from Windows 8 RTM. It is available for download in the Box.com widget to the right of this post,…
Read MoreX-Ways Forensics Practitioner’s Guide is coming!
Eric Zimmerman and Brett Shavers have started writing the “X-Ways Forensics Practitioner’s Guide”, due out toward the end of year 2013. Check back as to when the guide will be available. This guide intends to be the source…
Read MoreColin’s Final Version of his write protect application
This posting is copied from www.reboot.pro, posted by Colin Ramsden on his final version of the WinFE write protect tool. My thanks to Colin for his countless hours of work for which all of us will benefit. As to the future development of WinFE, maybe…
Read MoreA little reminder about ‘write protection’
If you try hard enough, you can circumvent just about anything. That includes hard drive write protection, whether you are booting to a Linux forensic OS, WinFE, and sometimes, even when using a physical hardware write protection device. There have…
Read MoreMounting Shadow Volumes
We’ve built our SEAT VM and added our target image to it as a virtual disk. The first thing that I do is verify that all of the shadow volumes are present. My first post presented a screen shot from the image file (MyImage) and depicted the…
Read More“Remote” Collections with WinFE, a neat trick
In civil litigation, the procedures for data collection are a little more relaxed as compared to criminal investigations, but cost is a huge factor. Typically, criminal suspects lose custody of their seized systems and won’t necessarily cooperate…
Read MoreAdding Our Target System to Our SEAT Workstation
In this step we’ll add our target system virtual disk to our SEAT VM. We already have the target (MyImage) virtual disk that we created, and we’ll add it to our system as in the next video. Add Virtual Disk As you saw, we chose to add the disk as…
Read MoreGetting Ready for a Shadow Volume Exam
We now have built a virtual machine from an image of the target system. Next, we’ll build a Windows 7 VM and configure it as our examination platform: Shadow Examination and Analysis Technique (SEAT) workstation. Building the VM basically is…
Read MoreHow many users of WinFE?
I don’t believe there is any means of determining how many users of WinFE exist, but the stats of just this blog may be an indication. So why would this be important? For one, using any forensic utility that has not been tried, proven, or commonly…
Read More