Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password

winfe

Subscribe to this list via RSS
FEB
15
2

But does it do Mac?

Posted by Brett Shavers
in  Digital Forensics


Just to clear up any questions on whether WinFE can 'do a Mac', well...it can.  And Linux too.  And of course it can do Windows as well.   As long as the machine can be booted to a WinFE CD or USB, then you can image the hard drive.  Actually, you can do a whole lot more than just image it...you can triage it, preview it, search it, or just copy files and folders from it.  If the drive is encrypted and you have the key, you can access the drive.  And what about VSS (Volume Shadow Service/Copies)....you can access those too, all through WinFE.

I can promise that as soon as you build a WinFE CD or bootable USB, you will regret not having done it months or years earlier (it's been around since 2008....).  And if building a forensic boot OS makes you hesitate at all, there is no need because if you use WinBuilder, it is as simple as pointing and clicking to fully customize your Windows FE CD or bootable USB.
0
  2450 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Andreas D
I think as long, as the suspicious machine has an Intel Architecture, Windows FE will boot. And from there, the Tools will work...... Read More
Tuesday, 15 February 2011 14:18
Guest — Brett Shavers
You are completely correct on why WinFE can boot to a Mac (intel Macs anyway). And that is one of the reasons WinFE is such a pow... Read More
Friday, 18 February 2011 14:40
2450 Hits
JAN
15
14

It's time to build your WinFE!

Posted by Brett Shavers
in  Digital Forensics

You can now download the WinFE WinBuilder.  Thanks to everyone that helped support this effort, it was well worth it.



As to a guide on how to use WinFE, it probably isn't really needed since WinFE is simply a forensic boot disc.  So, you might not need any help in putting WinFE to good use.  However...there may be a few things you didn't know you could do with WinFE that could be of interest.   Since that might be the case, here is a quick guide on tips on using WinFE as well as tips for building with WinBuilder.

Users Guide to WinFE

For support on how to use WinBuilder (troubleshooting, advanced features), check out the WinBuilder website at http://reboot.pro.

To reiterate some points about WinFE (and to hopefully prevent 'hate mail' coming to me from commercial products...), WinFE is an addition to your forensic toolkit. It doesn't replace any tools, only supplements what you are using anyway.   Commercial products that do the same thing that WinFE does work too, keep buying those if you want, you don't have to use WinFE.  And for the Linux lovers out there (Hey, I'm one of you guys too!), there is time and place for everything, sometimes WinFE is best, another time CAINE or DEFT or ???*nix may be best.

As far as anyone making a profit out of WinFE, no need to ask, because no one is;  it is a community project of customizing a Windows PE to fit your needs.

And yes, there are even some more neat things to be added to WinFE in the future...but as of now, you have access to a solid forensic environment.

For additional credits to this project;

This project uses the project Win7PE_SE as Base building, thank's to ChrisR for his great work ( Win7PE_SE http://reboot.pro/12427/).  Also, thanks to theYahoouk , JFX, Altorian, Lancelot, and RuiPaz with the Win7PE project on which this WinFE WinBuilder is based.
0
  6240 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Lancelot
Taking any tool or codes and using it for some other purposes is okey to the contributers of open-source free world. Even no cred... Read More
Sunday, 16 January 2011 01:44
Guest — Brett Shavers
Credit to all who I know that contributed to both WinFE and the WinBuilder WinFE project (if I've missed anyone, I'm happy to add ... Read More
Sunday, 16 January 2011 10:14
Guest — ChrisR
I'm agree with Lancelot. Thank you for the credit and for clarifying things. I think it's good to added Lancelot. He really provi... Read More
Sunday, 16 January 2011 20:11
6240 Hits
JAN
15
2

Portable Internet Evidence Finder and WinFE

Posted by Brett Shavers
in  Digital Forensics

Jad Saliba (of JadSoftware.com) has released an update to his Internet Evidence Finder/IEF in a portable version.  Now this sounds really good to have the ability to plug in a USB drive into a running machine to gather the information that IEF does.   But, to take it a step further, I tried IEF within a booted WinFE system.   And the result....it works perfectly!

To make sure you can get the full grasp of how neat this is, you can boot to WinFE and run IEF across the physical drive, without making any changes to the evidence.  This could be of real importance in an investigation such as a missing person case where internet/chat/webmail may be of immediate intelligence value.  Rather than imaging the hard drive to search for this data from the image, or booting the machine to its operating system and potentially overwriting pertinent data, you can boot to WinFE and run IEF on the write protected drive.   Of course, in a missing person case where chat is involved, it may also be most important to capture the volatile data FIRST before turning off the computer.

In civil case matters, this can be a fairly quick method of obtaining data relevant to the case matter onsite if imaging the hard drive is not allowed.

Although IEF doesn't run on Mac or Linux....if you boot a Mac or Linux machine with WinFE, IEF will run against that Mac or Linux hard drive ;)

0
  2503 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Nily
I am currently using a mac right now and was just wondering if i could get some info on how to boot a mac with WinFE. i am curren... Read More
Sunday, 27 March 2011 16:39
Guest — Brett Shavers
Just boot the Mac to a WinFE CD. As long as it an intel Mac, it'll boot to WinFE.
Monday, 28 March 2011 01:47
2503 Hits
    Previous     Next
6 7 8 9 10 11 12 13 14 15

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2023 Brett Shavers