Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password
Font size: + –
Subscribe to this blog post Unsubscribe
Report
Print
2 minutes reading time (439 words)

WinFE Course

Digital Forensics
Brett Shavers
Thursday, 15 May 2014
3666 Hits
4 Comments

I'm about halfway through the WinFE online course and then I'm sending it to a reviewer.  The topics and order of the curriculum are listed below.

I've added a multitude of build methods that will be documented and demonstrated in the online class.  It'll be recorded, so not a webinar where you have to close your door and tell the boss to stay out of your office during lunch. You will be able to watch it when you can and as much as you need.

imageIf you don't see something on the list that you would like to have added, now is the time to make the suggestion before I finish and upload the course.  I'm also uploading all the swag in form of batch files, white papers, wallpapers, applications, and anything else I have on WinFE for downloading.  Basically, everything you need will be in one place.

There is a test at the end of the course and you can take it if you like or not.  That is up to you to decide.  Personally, I'd take it just to say that I took coursework in a forensic tool that included an exam to test my knowledge.  This isn't a long course, but it is 'all things WinFE' wrapped up in one training program that you can take at home or during the lunch hour, about a forensic tool that anyone, and I mean literally anyone, can build on their laptop in Starbucks.  You don't need to be a programmer or software developer.  If you are a forensic examiner, you can build and use this tool.

WinFE doesn't do everything and doesn't work for every situation.  But for when you need to use forensically sound bootable environment, WinFE is pretty cool.

Curriculum

 

Introduction to the Course
Why take this course?
WARNINGS!

 

 

I. Forensic Booting of Evidence Computers
When, Why, How

 

 

II. Forensic Boot Operating Systems
Linux Forensic Operating Systems
Windows Forensic Environment (Windows FE, WinFE)

 

 

III. WinFE Basics
Creation and development of WinFE
WinFE Write Protection Tool
Disk Management & DiskPart
WinFE and Your Forensic Software


IV. Building the Windows Forensic Environment
Building the Basic WinFE
Building WinFE with WinBuilder
Building WinFE Lite
Building Mini-WinFE with Winbuilder
Building the Windows Triage Environment

 

 

V. Using WinFE
Forensic Data Collection (file copying, disk imaging)
Triage and Preview
Remote Booting and Collections
Onsite Forensic Analysis
Covert Collections/Sneak and Peeks
WinFE as a "Live" Tool
WinFE as an Electronic Discovery Tool
WinFE and Disk Encryption
Adding Drivers on the Fly

 

 

VI. Wrapping Up with WinFE
Summary

 

 

Exam
WinFE Qualification Exam

 

Tweet
Share on Pinterest
0
Tags:
winfe
Don't blame me...
Vote for the best book right away!

About the author

Brett Shavers

Brett Shavers

 

Comments 4

Guest
Guest - peet on Thursday, 15 May 2014 15:01

great idea - tnx in advance

0 Cancel Reply
great idea - tnx in advance
Cancel Update Comment
Guest
Guest - ChiefCham on Tuesday, 27 May 2014 01:06

I have been messing around with WINFE since 2009. This has been a great resource for my learning. And as a Digital Forensic Examiner has been very useful over the years to include recently imaging a Microsoft Surface Pro. Thanks for your contributions. I am looking forward to this course when you get it completed.

0 Cancel Reply
I have been messing around with WINFE since 2009. This has been a great resource for my learning. And as a Digital Forensic Examiner has been very useful over the years to include recently imaging a Microsoft Surface Pro. Thanks for your contributions. I am looking forward to this course when you get it completed.
Cancel Update Comment
Guest
Guest - Sean on Monday, 22 September 2014 02:36

Hi ChiefCham, did you manage to create a forensically sound image of a Surface Pro with WINFE? Could you provide an overview of the steps you took? Thanks!

0 Cancel Reply
Hi ChiefCham, did you manage to create a forensically sound image of a Surface Pro with WINFE? Could you provide an overview of the steps you took? Thanks!
Cancel Update Comment
Guest
Guest - ChiefCham on Friday, 26 September 2014 23:21

Yes I was able to get the image. Currently unable to get access to the paper and as soon as I do I will post it for use as well as any peer review.

0 Cancel Reply
Yes I was able to get the image. Currently unable to get access to the paper and as soon as I do I will post it for use as well as any peer review.
Cancel Update Comment
Guest
Tuesday, 07 February 2023

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://brettshavers.com/

direct link

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2023 Brett Shavers