Brett's Ramblings

Making the build even easier
Brett Shavers
Digital Forensics
There are a few WinFE builders creating a standalone, push button build for WinFE based on WinBuilder.  It will be set for defaults selected for forensic soundness and include only that what is needed for WinFE.  The goal is a about as close to a 'one-button build' as possible.  All you will need is your Windows install disc.  One button, done (wel...
A great interview with Author Eric Zimmerman.
Brett Shavers
Books
Hacking Exposed recently interviewed Eric in which he spoke a bit on the XWF Guide and his career.  Eric's experience in forensics shows in the book, which if you haven't heard, should be available on August 2nd.To make sure you can get a copy without waiting, consider a pre-order at Amazon :)[caption id="" align="alignnone" width="244"] Rather tha...
XWF Practitioner's Guide Date Change
Brett Shavers
Digital Forensics
Sometimes, a date change is a bad thing.  But this time, it's a good thing.Looks like we are way ahead of schedule going to print.  With the publisher's efforts (Syngress) combined with the speed of testing, writing, and editing talents of Eric Zimmerman, Jimmy Weg, and Stefan Fleischmann, we have pushed the print date from February 2014 ...
Running Autopsy 3 Digital Forensics Platform on WinFE Lite for Triage Forensics
Brett Shavers
Digital Forensics
No matter how you look at it, this is just plain cool: Running Autopsy 3 Digital Forensics Platform on WinFE Lite for Triage Forensics Something I'd never had thought to try, looks really cool.  The neat part is that Autopsy is free, as is WinFE, and when used together, make one heck of a triage tool for a price that can't be beat.Thanks to th...
Hitler rants about Encase training policies - Downfall parody
Brett Shavers
Digital Forensics
https://www.youtube.com/watch?feature=player_embedded&v=EcNGbd5Zxhc Levity in the digital forensics software world...(I didn't make the video, and i don't take the video as a slight against Encase, it's just a funny video).
XWFIM version 0.0.5.4 released
Brett Shavers
Digital Forensics
Just released version 0.5.4 of XWFIM.Changelog:Change: Renamed Settings.bin to xwfim.bin since people seemed to run both XWFIM and XWFRT from same directory and this caused problemsChange: Updated book cover image and URL when clicking on the book imageChange: Delete any old viewer directories before unzipping a new version to avoid file inconsiste...
"This book is going to be great!"
Brett Shavers
Books
"This book is going to be great!  The essential, accessible answer to the impenetrable density of XWF's help file". – Craig BallThere’s been more than few tweets about having to wait until October, but don’t worry, we are ahead of that schedule.    The most current target date for printing is September 3.The book is now in the hands of trusted revi...
The bar is now closed...
Brett Shavers
Books
As in, the book is done, no more to add, it's all done.   It's now in the hands of the publisher to proof, print, and distribute.   Accuracy checked by Stefan Fleischmann (developer of X-Ways Forensics),  Tech Edited by Jimmy Weg (an expert X-Ways user and superb tech editor), and written by Eric Zimmerman (who I have found to be a great writer and...
About those case studies.....
Brett Shavers
Books
We made a change with the case studies in the book, which some may not like...we didn't do the case studies chapter.Actually, we spent a lot of time trying to write up case studies, only to find that we were spending more effort and writing on the "how to do forensics' rather than the 'how to use XWF'.   As an example, writing about malware analysi...
Writing is done!
Brett Shavers
Books
All chapters are done, the writing is over, and the XWF Guide is just a few steps away from being put on paper (proofing, setting, and printing is all that is left).Having re-read the book, it is something I would have liked to have had when starting to use X-Ways Forensics in the beginning and while using it on cases.
Is WinFE still being used?
Brett Shavers
Digital Forensics
Yep!  Not only is WinFE still a viable project, it is being taught in more places, more often, to more people.  For example:The FAA: FAA78100041, (78100041) Creating a Windows FE DVDSearch at the Child Abuse and Family Summit in Oregon.HTCIA at a training session in Washington (state).Another HTCIA here (with instructions to build a WinFE).And a fe...
Take the XWF class or buy the book?
Brett Shavers
Digital Forensics
Regarding a post on twitter asking if training from X-Ways is worth it or just buy the book, I’d have to say taking the training is a good solution.  And so is buying the book. I favor training for almost everything (easier to learn from other’s mistakes…).  I also favor reading to self-learn and as a reference when needed.  I’ve per...
XWFIM updated
Brett Shavers
Digital Forensics
Just posted 0.0.5.3. This fixes a few issues related to checking for new versions when more than one zip file exists as they often do when it comes to prereleases. If you get an error about "more than one element" on startup, dont sent the error report, do not exit, then proceed to update using the built in updating feature. Worst case just re...
Case Studies
Brett Shavers
Digital Forensics
Here are some of the case studies we are working on for our current and last chapter: Electronic Discovery (IP theft, document collection, contract antedating) Consent Searches (triage/preview) Parole Searches (triage/preview) Malicious Software Intrusion Fraud Child Pornography Cell phone analysis Several of these are being submitted by contributo...
Multiple File Finder X-Tension for X-Ways Forensics
Brett Shavers
Digital Forensics
Here is a new X-Tension for XWF that does a few neat things, such as searching for specific files and adding them to the report table, and exporting files for external analysis: http://www.gaijin.at/en/xtmultifilefinder.php