Creating a VMware Virtual Machine from a Raw Image File
Welcome to my blog and first post! My aim is to provide tutorials that describe some of the things about which my colleagues have questions. I’m neither a seasoned blogger nor videographer, so please bear with me as I progress. I…
Read MoreWinFE “Lite”
Colin Ramsden has developed WinFE Lite, a build of WinFE that will run with a minimal amount of RAM (256MB). WinFE Lite is a very solid build and is detailed on Colin’s website (http://www.ramsdens.org.uk/). On his site, you will find everything…
Read MoreWinbuilder Tutorial
Check it out, http://reboot.pro/4111/ Perhaps the best and easiest tutorial I’ve seen on using Winbuilder. Just add the forensic write protect script and that’s it. You can customize as you see fit. Colin Ramsden is working on some really…
Read MoreFor those that still haven’t tried WinFE….
If you still haven’t decided to download it and try it, here is a QuickStart Guide to show only what you need to get going. [scribd id=91022843 key=key-13pbj0h95qsj4sio15zu mode=list]
Read MoreWinFE Script Updated
Colin’s Write Protect Script (wp.script) is available, but still considered Beta (and as with any forensic utility, test – test – test). You can download today’s version here. wp.script. To make sure you get the most recent…
Read MoreColin’s Write Protect Application
Here it is, Colin Ramsden’s WinFE write protect application! Although long in waiting, it is finally here. Colin worked diligently on making this work without making Microsoft unhappy. Documentation is forthcoming on the use of his application,…
Read MoreBuilding your WinFE Update
For those that have been using WinFE and wanting to know about recent updates, I have only a little news to mention. WinFE is still just as good today as when Troy Larson first created it, so not much in the update area there. WinFE still boots the…
Read MoreAn update to a long awaited project
It’s been awhile, a long while, since there has been anything added to the WinFE project, and the bad news is that nothing is new other than Microsoft not quite accepting of Colin Ramsden’s write protect tool. As that is not good news, both…
Read MoreSharing the love with WinFE
There have been numerous presentations showing how to build and use a WinFE boot disc around the world. Most recently I see that IACIS has given a demo this year along with several HTCIA Chapters and a DOD conference as well. A write up of Imaging a…
Read MoreFriendly reminders are always nice
Always test your tools (this includes WinFE). Considering that NIST recently discovered that some Ubuntu based forensic boot discs could make modifications to a booted suspect drive (modifies the $logfile upon booting….), these sort of news…
Read More