Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password

winfe

Subscribe to this list via RSS
DEC
14
1

MobaLiveCD

Posted by Brett Shavers
in  Digital Forensics

Here is a neat and FREE app to test your Live CDs.  Not sure how I missed this one, but instead of creating an entire virtual machine to boot a ISO for testing, you can just run the ISO with MobaLiveCD (http://mobalivecd.mobatek.net/en/).  QEMU opens a virtual machine window that much faster on your screen.



This may just cut down the number of cup mats I usually make when burning CDs...

0
  2207 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent comment in this post
Guest — dubiaku
True. Looks useful. But I already have a VM in VMware called "ISO Boot" that is specifically for this. No need to make a new VM ea... Read More
Tuesday, 14 December 2010 15:13
2207 Hits
NOV
30
2

WinFE and Triage

Posted by Brett Shavers
in  Digital Forensics

On the subject of triage, I have some thoughts which some companies may not like to hear (at least companies selling triage software or 'triage computer systems'...).

Here are some problems I see with several triage systems available;

-Any triage tool that is marketed that anyone can plug it in and capture all responsive data and even create a forensic image, without having any knowledge of computers is a tool I would keep at a safe distance from custodians of data...Plug n' Play to capture evidence or triage a system?  How many problems? Let me count the ways...

-Any triage tool that is restricted to run on a specific computer is one that has just limited itself out of the market.  Since when do you want a tool that can only run on a specific computer you must buy?  Sorta useless if something happens to that computer.

-Any triage tool that professes to magically find all relevant data, even in the hands of untrained persons...wow.    Are you sure its finding what you need?

Why not triage a computer like everyone did in the old days.  Boot to a forensic OS (pick your flavor of OS) and use a tool you always use to find what you need to find.  Every case is different, so every triage is bound to be different.   On one computer, you may need to see the registry, whereas on another, you need to see the images.



And untrained persons triaging machines?  Good luck.  Emergency rooms don't use non-medical staff to triage patients, why would anyone use non-computer trained persons to triage computers?

As for a pretty good system for triage, build a WinFE disc (it's free, you don't need to buy anything other than a CD) and put your favorite forensic tools on it, the ones you use all the time.  Now you have a triage system.   No, more than that, you have a complete Windows Forensic Environment to look for exactly the things you need to look for.   Done right the first time.

So the next time you see a "Triage System" that is plug n'play simple, that decides what data you need to be collected, and that you just sit back and let it work, think about it a little more.  As for me, I want to push the buttons and triage based on what I need and what I see when I am looking at the data.

0
  2250 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Andrew Sheldon
Hi Brett, Your comments are interesting but your conclusions are, IMHO, missing the mark by some way (and yes, we produce SPEKTOR... Read More
Monday, 29 November 2010 23:58
Guest — Brett Shavers
Thanks for your comment. There is certainly a situation for everything. I don't believe there is a single answer to the triage ... Read More
Tuesday, 30 November 2010 00:42
2250 Hits
OCT
29
6

What makes WinFE better/different than other forensic boot discs?

Posted by Brett Shavers
in  Digital Forensics
I've been asked on occasion, "What makes WinFE better or different than any other boot disc?".

WinFE is Windows based, not Linux.  For someone not experienced in Linux, the Windows environment may be easier to use due to familiarity with Windows.

Additionally, WinFE allows you to use your Windows based forensic applications in a forensically booted environment.  Rather than using a Linux CD and image with Linen, you can use a Windows CD and image with the full version of Encase or FTK Imager or X-Ways Forensics or other Windows based tool.

If your lab is Linux based, then WinFE may not be as comfortable as using a Linux based tool, but still may be an option to keep on hand (the opposite still remains true, if you focus on using Windows based tools, have some Linux options on hand as well).

Lastly, WinFE is updated by YOU, when YOU need it updated.  There is no need to wait for a distro to be upgraded every 6 months or longer before you can download it.  Current Linux ISO's available online still may have older versions of software that are outdated.  With WinFE, if any tool is updated/upgraded, you can do it immediately and always have the latest apps.

Other than that, its just user preference.X-Ways Forensics Practitioner's Guide
0
  2705 Hits
Tags:
winfe
Tweet
Share on Pinterest
Recent Comments
Guest — Cainer
Why do you affirm this: "Current Linux ISO’s available online still may have older versions of software that are outdated" Did you... Read More
Sunday, 31 October 2010 16:22
Guest — WinFE
I like CAINE as it is one of the most current updated Linux forensics distros. In a presentation I just gave, I complimented CAIN... Read More
Monday, 01 November 2010 00:58
Guest — Cainer
Ok CAINE or better WinTaylor 2.1 has FTK Imager 2.9.0.5 and Nirsoft Mega Report, but these are the Windows Live analisys tools. In... Read More
Monday, 01 November 2010 01:05
2705 Hits
    Previous     Next
8 9 10 11 12 13 14 15 16 17

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2023 Brett Shavers