Skip to content
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe
Brett's Ramblings Brett's Ramblings Brett's Ramblings
Brett's Ramblings Brett's Ramblings Brett's Ramblings
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Close

Search

  • Home
  • My books
  • About me
  • Hire me.
  • Contact
Subscribe

Build questions

By Brett Shavers
October 27, 2012
4

I’ve fielded a few questions via email on building a WinFE over the past few days that I’d like to share on the WinFE blog.

Since Windows FE (Windows Forensic Environment, WinFE) is simply a Windows PE that doesn’t automount hard drives, the build of a WinFE beyond that purpose is purely for customization and specific needs.   Those needs can be adding specific drivers,  programs, supporting files, Bitlocker support, network ability, and even making it pretty with a custom wallpaper.

Building a WinFE can be done in one of several ways;

1)  Command line (or batch files via a command line),

2)  Any GUI interface made to create a WinPE (such as Winbuilder),

3)  Or the method developed by Colin Ramsden.

My notes on each method:

1)   Command line – builds a WinFE the quickest, using only the registry settings created by Troy Larson.   A very minimal build, great for older computers with little RAM.   Pre-made batch files can be downloaded from the “Box” to your right on this page.

2)  GUI interfaces – I’ve tried several different programs and have selected WinBuilder as the easiest.   There are many scripts (additional features/programs) that can be added easily to the build that can practically create a near full-fledged Windows OS on a CD/DVD/USB.  It is also fairly easy to get many programs (FTK Imager, Encase, X-Ways, etc..) running in full mode.

BUT, adding  more features, programs, and scripts that are added results in more RAM needed in the evidence machine, more errors you will have during the build when adding scripts that may not be compatible with other scripts, and more testing to ensure the build works as a forensic application.

3)  Colin Ramsden’s method – The best of both worlds.  A little more manual effort to build, but runs well on older machines and is a solid build.   More details at http://www.ramsdens.org.uk/


Discover more from Brett's Ramblings

Subscribe to get the latest posts sent to your email.

Author

Brett Shavers

Follow Me
Other Articles
Previous

WinFE updated

Next

2012 in review

4 Comments
  1. Lancelot says:
    June 23, 2012 at 02:09

    I guess you mean Win7PESE on 2 ;)
    http://theoven.org/index.php?board=20.0

    For a while I see you have wrong terminology, winbuilder is only a batcher, like cmd,

    giving example:
    instead of “cmd” you say “Colin’s new method”
    instead of “winbuilder” you should say “Win7PESE”
    ps: I like Colin’s method :>

    Forensic plugins and tools are good,
    For a wider audiance (distribution), I recommend a plugin page, tutorialing adding WinFE tools
    ex:
    Plugin for Win7PESE:
    Download
    put to …. folder …..

    Plugin for MakePE3
    Download
    …….

    Plugin for MultiPE-LiveSystemPRO
    Download
    …….

    ;)

    Reply
  2. Brett Shavers says:
    June 26, 2012 at 10:09

    Nice suggestions, much clearer than I could have said it. Thanks :)

    Reply
  3. Cory says:
    September 25, 2015 at 09:02

    If someone were to help me I would be greatly appreciative! I tried to make a win de disk. Tried to add ftk and encase imager. All worked great except the imagers were nowhere to be found. I followed the directions to a tee and still nothing. Being new to all this I’m asking for some help! I’m sure I am missing a step. Thanks all

    Reply
  4. Cory says:
    September 25, 2015 at 09:04

    Sorry that should have read I’m building a win FE disk. Sorry

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • X
  • LinkedIn
  • Bluesky
  • Instagram
  • Mastodon
  • FACT Attribution Framework
  • https://www.dfir.training
  • https://winfe.wordpress.com
  • https://xwaysforensics.wordpress.com

My recent interview on a really good DFIR podcast (Parsing the Truth).

  • X
  • LinkedIn
  • Instagram
  • Bluesky
  • Facebook
  • Mastodon
  • YouTube
Copyright 2026 — Brett's Ramblings. All rights reserved.