A little reminder about ‘write protection’
If you try hard enough, you can circumvent just about anything. That includes hard drive write protection, whether you are booting to a Linux forensic OS, WinFE, and sometimes, even when using a physical hardware write protection device. There have…
Read MoreMounting Shadow Volumes
We’ve built our SEAT VM and added our target image to it as a virtual disk. The first thing that I do is verify that all of the shadow volumes are present. My first post presented a screen shot from the image file (MyImage) and depicted the…
Read More“Remote” Collections with WinFE, a neat trick
In civil litigation, the procedures for data collection are a little more relaxed as compared to criminal investigations, but cost is a huge factor. Typically, criminal suspects lose custody of their seized systems and won’t necessarily cooperate…
Read MoreAdding Our Target System to Our SEAT Workstation
In this step we’ll add our target system virtual disk to our SEAT VM. We already have the target (MyImage) virtual disk that we created, and we’ll add it to our system as in the next video. Add Virtual Disk As you saw, we chose to add the disk as…
Read MoreGetting Ready for a Shadow Volume Exam
We now have built a virtual machine from an image of the target system. Next, we’ll build a Windows 7 VM and configure it as our examination platform: Shadow Examination and Analysis Technique (SEAT) workstation. Building the VM basically is…
Read MoreHow many users of WinFE?
I don’t believe there is any means of determining how many users of WinFE exist, but the stats of just this blog may be an indication. So why would this be important? For one, using any forensic utility that has not been tried, proven, or commonly…
Read MoreCreating a VMware Virtual Machine from a Raw Image File
Welcome to my blog and first post! My aim is to provide tutorials that describe some of the things about which my colleagues have questions. I’m neither a seasoned blogger nor videographer, so please bear with me as I progress. I…
Read MoreWinFE “Lite”
Colin Ramsden has developed WinFE Lite, a build of WinFE that will run with a minimal amount of RAM (256MB). WinFE Lite is a very solid build and is detailed on Colin’s website (http://www.ramsdens.org.uk/). On his site, you will find everything…
Read MoreWinbuilder Tutorial
Check it out, http://reboot.pro/4111/ Perhaps the best and easiest tutorial I’ve seen on using Winbuilder. Just add the forensic write protect script and that’s it. You can customize as you see fit. Colin Ramsden is working on some really…
Read MoreFor those that still haven’t tried WinFE….
If you still haven’t decided to download it and try it, here is a QuickStart Guide to show only what you need to get going. [scribd id=91022843 key=key-13pbj0h95qsj4sio15zu mode=list]
Read More