Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password
Brett Shavers

Brett Shavers

JAN
15
14

It's time to build your WinFE!

Posted by Brett Shavers
in  Digital Forensics

You can now download the WinFE WinBuilder.  Thanks to everyone that helped support this effort, it was well worth it.



As to a guide on how to use WinFE, it probably isn't really needed since WinFE is simply a forensic boot disc.  So, you might not need any help in putting WinFE to good use.  However...there may be a few things you didn't know you could do with WinFE that could be of interest.   Since that might be the case, here is a quick guide on tips on using WinFE as well as tips for building with WinBuilder.

Users Guide to WinFE

For support on how to use WinBuilder (troubleshooting, advanced features), check out the WinBuilder website at http://reboot.pro.

To reiterate some points about WinFE (and to hopefully prevent 'hate mail' coming to me from commercial products...), WinFE is an addition to your forensic toolkit. It doesn't replace any tools, only supplements what you are using anyway.   Commercial products that do the same thing that WinFE does work too, keep buying those if you want, you don't have to use WinFE.  And for the Linux lovers out there (Hey, I'm one of you guys too!), there is time and place for everything, sometimes WinFE is best, another time CAINE or DEFT or ???*nix may be best.

As far as anyone making a profit out of WinFE, no need to ask, because no one is;  it is a community project of customizing a Windows PE to fit your needs.

And yes, there are even some more neat things to be added to WinFE in the future...but as of now, you have access to a solid forensic environment.

For additional credits to this project;

This project uses the project Win7PE_SE as Base building, thank's to ChrisR for his great work ( Win7PE_SE http://reboot.pro/12427/).  Also, thanks to theYahoouk , JFX, Altorian, Lancelot, and RuiPaz with the Win7PE project on which this WinFE WinBuilder is based.
  6240 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Lancelot
Taking any tool or codes and using it for some other purposes is okey to the contributers of open-source free world. Even no cred... Read More
Sunday, 16 January 2011 01:44
Guest — Brett Shavers
Credit to all who I know that contributed to both WinFE and the WinBuilder WinFE project (if I've missed anyone, I'm happy to add ... Read More
Sunday, 16 January 2011 10:14
Guest — ChrisR
I'm agree with Lancelot. Thank you for the credit and for clarifying things. I think it's good to added Lancelot. He really provi... Read More
Sunday, 16 January 2011 20:11
6240 Hits
JAN
15
2

Portable Internet Evidence Finder and WinFE

Posted by Brett Shavers
in  Digital Forensics

Jad Saliba (of JadSoftware.com) has released an update to his Internet Evidence Finder/IEF in a portable version.  Now this sounds really good to have the ability to plug in a USB drive into a running machine to gather the information that IEF does.   But, to take it a step further, I tried IEF within a booted WinFE system.   And the result....it works perfectly!

To make sure you can get the full grasp of how neat this is, you can boot to WinFE and run IEF across the physical drive, without making any changes to the evidence.  This could be of real importance in an investigation such as a missing person case where internet/chat/webmail may be of immediate intelligence value.  Rather than imaging the hard drive to search for this data from the image, or booting the machine to its operating system and potentially overwriting pertinent data, you can boot to WinFE and run IEF on the write protected drive.   Of course, in a missing person case where chat is involved, it may also be most important to capture the volatile data FIRST before turning off the computer.

In civil case matters, this can be a fairly quick method of obtaining data relevant to the case matter onsite if imaging the hard drive is not allowed.

Although IEF doesn't run on Mac or Linux....if you boot a Mac or Linux machine with WinFE, IEF will run against that Mac or Linux hard drive ;)

  2503 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Nily
I am currently using a mac right now and was just wondering if i could get some info on how to boot a mac with WinFE. i am curren... Read More
Sunday, 27 March 2011 16:39
Guest — Brett Shavers
Just boot the Mac to a WinFE CD. As long as it an intel Mac, it'll boot to WinFE.
Monday, 28 March 2011 01:47
2503 Hits
DEC
19
2

Updated video and other things

Posted by Brett Shavers
in  Digital Forensics

If you haven't seen Marc Remmert's video on creating a WinFE ISO, here is his video.  Although the WinBuilder method greatly simplifies what Marc shows in his video, it certainly recommended to see what is actually happening to a Win"P"E to make it into a Win"F"E, no matter the process used, at least understand the changes being made, the reason for the changes, and the validation of the changes.  And for those that insist that WinFE is not WinFE and that it is WinPE...well, you are sorta correct.  WinFE is the 'forensic' modification of a WinPE, so it really is something different.

[youtube=http://www.youtube.com/watch?v=J3T5wnPiObI]

On the WinBuilder topic, a great group of beta testers have started to put WinBuilder through its paces.  Again, although the end result is that you will be able to create a WinFE ISO with a few clicks, it is best to know what is happening behind the scenes and Marc's video gives you that insight.

  2235 Hits
Tags:
winfe
Tweet
Recent Comments
Guest — Isaac
When do you expect the WinBuilder available version of WinFE to be avaiable for download to non-beta testers? When will you relea... Read More
Monday, 10 January 2011 07:03
Guest — Brett Shavers
Working on a short 'How To" written guide and video to accompany it. But to answer your question...I'm working to finish it in 2 ... Read More
Monday, 10 January 2011 07:16
2235 Hits
    Previous     Next
105 106 107 108 109 110 111 112 113 114

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2023 Brett Shavers