Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password

Digital Forensics

MAR
19
12

Colin's Write Protect Application

Posted by Brett Shavers
in  Digital Forensics

Here it is, Colin Ramsden's WinFE write protect application!




Although long in waiting, it is finally here.   Colin worked diligently on making this work without making Microsoft unhappy.  Documentation is forthcoming on the use of his application, but as you can see, it is really easy to figure out how to manage your disks.

Other little features may be coming in the future, but for now, say so long to DiskPart.

You can download the WinBuilder script from the BoxNet on this site (to your right of the page) and it will also be made available on the www.reboot.pro website.  The file, "wp.script" needs to be placed in the "tweaks" folder in the WinBuilder folder structure.

For support on creating a WinFE ISO using WinBuilder, consult the forums at www.reboot.pro.
0
  3113 Hits
Tweet
Share on Pinterest
Recent Comments
Guest — cramsden
Guys, Time to apply your safety catches before someone has a negligent discharge! This version of the script is 1.0.0.141 and sh... Read More
Monday, 19 March 2012 19:33
Guest — cramsden
Well, I've found a bug already! I'll have a new build put together, which will be sent to Brett today!
Monday, 19 March 2012 19:48
Guest — cramsdenColinR
1.0.0.149 is now released, this should address the bug discovered in the post above, as well as a better disk information dialog.... Read More
Tuesday, 20 March 2012 08:22
3113 Hits
JAN
03
0

Building your WinFE Update

Posted by Brett Shavers
in  Digital Forensics
For those that have been using WinFE and wanting to know about recent updates, I have only a little news to mention.    WinFE is still just as good today as when Troy Larson first created it, so not much in the update area there.  WinFE still boots the same computer systems and you can do the same forensic work as before, not much has changed since then.   DiskPart is still the primary (only) method to toggle drives on/offline, which isn't difficult to do.  Still command line, but easy commands to use.

WinFE Batch File Building Method


And building WinFE is the same as before, no changes there either.  If you use the batch file method, you can write your own or you can download pre-made batch files using the Box.net widget on this site to the right.   Several to choose and modify to suit your preferences.

The location of the batch files on this blog looks like the below screenshot, so if you don't see it, you may need to have Java enabled in your browser.

All the batch files are in this zip file.


WinFE WinBuilder Building Method


If you are using WinBuilder (www.reboot.pro), there have been a continual update of the WinFE scripts by RoyM.  The reboot.pro site is also the best place for forum support directly with the script writers if you have problems building your WinFE.  RoyM (and others) has taken a great lead in the WinFE WinBuilder development.  My hat is off to all the contributors.

Other Forensic Boot Systems


The "other" forensic boot systems have had a few updates, some major.  I would highly recommend checking out Raptor, CAINE, and DEFT!  A major difference between WinFE and several of the Linux forensic boot systems is that many of the Linux systems are pre-made forensic OS's, with freeware/open source tools already installed.  WinFE requires you to add the apps you want to use, which may be freeware, open source, or commercial.    A more complete forensic G0-Bag Kit has all of them....just in case....

 
0
  2046 Hits
Tweet
Share on Pinterest
2046 Hits
SEP
27
1

An update to a long awaited project

Posted by Brett Shavers
in  Digital Forensics
It's been awhile, a long while, since there has been anything added to the WinFE project, and the bad news is that nothing is new other than Microsoft not quite accepting of Colin Ramsden's write protect tool.   As that is not good news, both Troy and Colin are working toward an effort that may meet Microsoft's needs for an acceptable (to Microsoft...) write protect application other than DiskPart.

Sorry for the news on no news, but WinFE still works as it is, you just need to use the command line to toggle drives on/offline.
0
  2000 Hits
Tweet
Recent comment in this post
Guest — peet
it would be possible to publish the wrapper on it's own, and people are allowed to add whatever they want to their PE, FE, ..., do... Read More
Tuesday, 27 September 2011 15:59
2000 Hits
    Previous     Next
85 86 87 88 89 90 91 92 93 94

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2022 Brett Shavers