Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password
Brett Shavers

Brett Shavers

JUN
11
2

Current and Future Development of Windows FE

Posted by Brett Shavers
in  Digital Forensics
The WinFE journey…

From Troy Larson’s first vision of the Windows Forensic Environment to the improvements currently being made, WinFE is set to become one of the best forensic boot disks/USBs available.

The ease to which it can be created has been simplified greatly by Björn Ganster’s automated batch files (my initial batch files were elementary compared to Björn’s improvements).  Colin Ramsden is working some aspects of WinFE that really are impressive, such as GUI’s for WinFE, installing hasps drivers, mapping network drives, Apple HFS+ drivers, other program installations help, etc…   Jad Saliba of JadSoftware has plans to work on making IEF run in the WinFE environment.  Add these to Matt Churchhill’s version “WindowsRipper” modified from Harlan Carvey’s  “RegRipper” and you are set to add such a triage functionality to WinFE, that given 20 minutes in front of a computer, you may be able to get everything you need from the machine.  You can either determine if the computer is worth seizing at all, or in the case of a (legal!) snatch and grab op, grab only the data of importance from a host computer without the (criminal/terrorist) user ever knowing their computer was touched.

It is incredible what a group of contributors can have on a project that benefits the community. If you haven't gotten access to the shared folder, you can use this link to sign up for DropBox and I'll share the folder with you.  If you have already gotten a DropBox account, send me an email so I can share the folder with your current login.  I'd make the folder public, but would rather have at least one step to get to it rather than it open to the world so easily.  The neat thing about the shared folder, is that when someone puts in an updated batch file, you have access to it immediately.


For anyone waiting for WinFE to be available for one single and complete download...it won't happen.  There are some MS licensing issues that prevent that, so sit down for a bit, take a look at how to make one, and get started!  You won't regret it.
  3150 Hits
Tweet
Recent Comments
Guest — Rob
Great info..and good to see there is Interest in this project from Developers/coders..
Monday, 14 June 2010 00:18
Guest — ihuntcrows
hi my dropbox email thing is ihuntcrows@aol.com or ihuntcrows. im interested in this shared folder. thanks
Thursday, 16 December 2010 18:47
3150 Hits
JUN
09
2

Internet Evidence Finder (IEF): interview with Jad Saliba of JADSoftware.com

Posted by Brett Shavers
in  Digital Forensics
Jad Saliba, developer of the Internet Evidence Finder (IEF) and other neat software was interviewed recently and mentioned that he has plans to make IEF run portable on WinFE.  If you haven't purchased a copy of IEF (free to LE), take a look at it.  This would be a fantastic triage type application on WinFE as it searches for chat, email fragments (including Gmail!), Facebook snippets and fragments, Limewire, and more.

The day IEF is able to run on WinFE is the day I add it to mine ;)
  2247 Hits
Tweet
Recent Comments
Guest — KP
I donated to the IEF project back before Jad started charging for it and he was kind enough to give me two licenses for it. I've ... Read More
Wednesday, 09 June 2010 13:51
Guest — Rob
Agree..Thanks for the Effort on making this work with FE.. Good stuff!
Thursday, 10 June 2010 04:32
2247 Hits
JUN
02
8

More Windows FE and triage notes (WindowsRipper?)

Posted by Brett Shavers
in  Digital Forensics

Matt Churchhill (http://mattchurchill.net/2010/06/windowsripper/) has been doing some work to supercharge RegRipper.  Take a look at his video and while watching, consider how this can affect your method to triage a computer when booted to WinFE...

[youtube=http://www.youtube.com/watch?v=r4nBUXYGkBw&hl=en_US&fs=1&border=1]

  2828 Hits
Tags:
winfe
Tweet
Recent Comments
Guest — Rob
Am I correct that once you assign a drive letter to the Volume you are going to be touching the Drive in WinFE?
Wednesday, 02 June 2010 10:30
Guest — Anonymous
If you set a volume to read only, the disk is written to (offset 0x417). If a disk is set to read only, it is not written to. So... Read More
Wednesday, 02 June 2010 11:09
Guest — Matt C
Thanks for the link, Brett. I hadn't thought of putting this on WinFE before, but it's a great idea.
Wednesday, 02 June 2010 11:32
2828 Hits
    Previous     Next
108 109 110 111 112 113 114 115 116 117

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2023 Brett Shavers