The day IEF is able to run on WinFE is the day I add it to mine ;)
Matt Churchhill (http://mattchurchill.net/2010/06/windowsripper/) has been doing some work to supercharge RegRipper. Take a look at his video and while watching, consider how this can affect your method to triage a computer when booted to WinFE...
[youtube=http://www.youtube.com/watch?v=r4nBUXYGkBw&hl=en_US&fs=1&border=1]
This should be a neat webinar on Windows FE and Triage.
https://www2.gotomeeting.com/register/892321554
Check the "Using WinFE" page for tips on using WinFE for not only triage/preview, but other ways to use the tool. Until I hear otherwise, I have found that X-Ways Forensics is the most complete forensic tool that can run on the Windows Forensic Environment without having to install dongles or hasps, dependent files, or other installation hassles. Simply copying the X-Ways Forensic folder runs the program. Take a look at the Triage/Preview link on this site for some things XWF can do in this sort of scenario.
Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.
© 2023 Brett Shavers