Brett's Ramblings

Friendly reminders are always nice
Brett Shavers
Digital Forensics
Always test your tools (this includes WinFE).  Considering that NIST recently discovered that some Ubuntu based forensic boot discs could make modifications to a booted suspect drive (modifies the $logfile upon booting....),  these sort of news breaks are a friendly reminder to test your tools.  Additionally, when 'bugs' are found in forensic tools...
How easy (or difficult) is it to build a WinFE with WinBuilder?
Brett Shavers
Digital Forensics
An easy quickstart guide to build your WinFE ISO... 1) Extract WinBuilder to the root of your C:/ drive2) Run WinBuilder3) Click 3 buttons and you are done.If you want more features, such as additional programs, network support, audio, more drivers, customized wallpaper, create a bootable WinFE flashdrive, etc..., then you just need to push a few m...
Triage Notes and WinFE
Brett Shavers
Digital Forensics
One of the biggest benefits (besides imaging storage media) of WinFE is the ability to create a customized triage system at virtually no cost.  Purchasing a pre-made system may not be an issue when only one or a few systems are needed, but when outfitting an entire unit or perhaps an entire police department, bulk purchases of software to be i...
OSForensics
Brett Shavers
Digital Forensics
Giving more usability to WinFE, OSForensics has several features that I can see being beneficial in triage of a system with OSForensics.  OSForensics can be run on a live system (not the optimal decision in most cases), a mounted image, or in a forensically booted WinFE system.The program's interface is simple and encompasses quite a bit of the bas...
WinFE Demo Online
Brett Shavers
Digital Forensics
I'll be giving a demo of WinFE to www.ctin.org on March 10 (online).  I'll be showing some neat developments in the work as well as discuss solving build problems.There are a few spots left and you have to be a CTIN member to view the presentation.  But maybe it is something worthwhile to join anyway as most all the training is free to me...
But does it do Mac?
Brett Shavers
Digital Forensics
Just to clear up any questions on whether WinFE can 'do a Mac', well...it can.  And Linux too.  And of course it can do Windows as well.   As long as the machine can be booted to a WinFE CD or USB, then you can image the hard drive.  Actually, you can do a whole lot more than just image it...you can triage it, preview it, s...
It's time to build your WinFE!
Brett Shavers
Digital Forensics
You can now download the WinFE WinBuilder.  Thanks to everyone that helped support this effort, it was well worth it.As to a guide on how to use WinFE, it probably isn't really needed since WinFE is simply a forensic boot disc.  So, you might not need any help in putting WinFE to good use.  However...there may be a few things you did...
Portable Internet Evidence Finder and WinFE
Brett Shavers
Digital Forensics
Jad Saliba (of JadSoftware.com) has released an update to his Internet Evidence Finder/IEF in a portable version.  Now this sounds really good to have the ability to plug in a USB drive into a running machine to gather the information that IEF does.   But, to take it a step further, I tried IEF within a booted WinFE system.   An...
Updated video and other things
Brett Shavers
Digital Forensics
If you haven't seen Marc Remmert's video on creating a WinFE ISO, here is his video.  Although the WinBuilder method greatly simplifies what Marc shows in his video, it certainly recommended to see what is actually happening to a Win"P"E to make it into a Win"F"E, no matter the process used, at least understand the changes being made, the...
Do you wanna be a beta tester for WinFE?
Brett Shavers
Digital Forensics
Just before the latest WinBuilder WinFE gets released, would you like to take it on a test run first before the rest of the world gets it?  There are some neat features (Bitlocker support, DiskPart batch file, plus others), but the main concern is testing to see if anything needs to be fixed, corrected, added, or taken away from the build.If y...
WinBuilder Revisited
Brett Shavers
Digital Forensics
A big thanks to Royal Meier for providing  a script to modify the registry with a WinBuilder Win7PE build.   What I thought would be a difficult task of using WinBuilder to build a WinFE ISO, is turning out to be quite simple, at least for Royal Meier (he makes it look simple anyway).I am planning that "the" WinFE WinBuilder will be ...
MobaLiveCD
Brett Shavers
Digital Forensics
Here is a neat and FREE app to test your Live CDs.  Not sure how I missed this one, but instead of creating an entire virtual machine to boot a ISO for testing, you can just run the ISO with MobaLiveCD (http://mobalivecd.mobatek.net/en/).  QEMU opens a virtual machine window that much faster on your screen.This may just cut down the numbe...
WinFE and Triage
Brett Shavers
Digital Forensics
On the subject of triage, I have some thoughts which some companies may not like to hear (at least companies selling triage software or 'triage computer systems'...).Here are some problems I see with several triage systems available;-Any triage tool that is marketed that anyone can plug it in and capture all responsive data and even create a forens...
What makes WinFE better/different than other forensic boot discs?
Brett Shavers
Digital Forensics
I've been asked on occasion, "What makes WinFE better or different than any other boot disc?".WinFE is Windows based, not Linux.  For someone not experienced in Linux, the Windows environment may be easier to use due to familiarity with Windows.Additionally, WinFE allows you to use your Windows based forensic applications in a forens...
FTK Imager 3.0 in the Windows Forensic Environment
Brett Shavers
Digital Forensics
By now, most everyone involved with forensics knows about the latest release of FTK Imager 3.0.   In my opinion, this is perhaps the best release ever of FTK Imager and probably one of the top releases of software this  year because of one of the newest features and the price (FREE and MOUNTS IMAGES!).  Given other expensive software...