What makes WinFE better/different than other forensic boot discs?
I’ve been asked on occasion, “What makes WinFE better or different than any other boot disc?”.
WinFE is Windows based, not Linux. For someone not experienced in Linux, the Windows environment may be easier to use due to familiarity with Windows.
Additionally, WinFE allows you to use your Windows based forensic applications in a forensically booted environment. Rather than using a Linux CD and image with Linen, you can use a Windows CD and image with the full version of Encase or FTK Imager or X-Ways Forensics or other Windows based tool.
If your lab is Linux based, then WinFE may not be as comfortable as using a Linux based tool, but still may be an option to keep on hand (the opposite still remains true, if you focus on using Windows based tools, have some Linux options on hand as well).
Lastly, WinFE is updated by YOU, when YOU need it updated. There is no need to wait for a distro to be upgraded every 6 months or longer before you can download it. Current Linux ISO’s available online still may have older versions of software that are outdated. With WinFE, if any tool is updated/upgraded, you can do it immediately and always have the latest apps.
Other than that, its just user preference.
Discover more from Brett's Ramblings
Subscribe to get the latest posts sent to your email.
Show CommentsWhy do you affirm this:
“Current Linux ISO’s available online still may have older versions of software that are outdated”
Did you try Caine? http://www.caine-live.net?
I like CAINE as it is one of the most current updated Linux forensics distros. In a presentation I just gave, I complimented CAINE as one of the most updated and freely available forensic boot discs. I also like DEFT (http://www.deftlinux.net/), but as an example DEFT has FTK Imager 2.6.1 which is several versions older than the current 3.0. Other Linux distros such as SPADA may not have been updated since 2005.
So, some are updated, others are not. With WinFE, you build it to your specs and burn it with current version tools. However(!), if you can re-master a Linux distro, this is not an issue as you can upgrade or create your own Linux forensic boot CD.
As a side note, I personally have copies of every Linux forensic CD (including CAINE…) on my desk and carry onsite for every case. WinFE is just my personal first choice, backed up by Linux.
Ok CAINE or better WinTaylor 2.1 has FTK Imager 2.9.0.5 and Nirsoft Mega Report, but these are the Windows Live analisys tools.
In any case you can install Caine and upgrade its tool ;)
I remind you that you can use libewf or Guymager to get the EWF image files, even if many people prefer Raw or AFF.
Personally, I would like to have WinFe, but I guess that is only for LE ;)
Thank you for your clearness.
WinFE is not LE only, its yours for the making (directions are here: http://www.forensicfocus.com/downloads/WinFE.pdf).
I’d recommend a complete solution of forensic boot discs would be to include both a WinFE CD and at least 1 Linux distro such as CAINE. I also suggest this idea of having multiple forensic boot options on the website as well: http://winfe.wordpress.com/other-forensic-boot-options/
Hi WinFE,
sorry but what do you say about DEFT Linux is not true because the develop team release a new version every year since 2005! The release 6 is coming… and, for example, contain FTK imager 3.
Bye and good luck!
I certainly am not intending to antagonize any Linux users…even in my home, I run Linux, so nothing against Linux. And I absolutely recommend and practice that proficient forensic examiners use (or at least possess) both Linux and Windows OS imaging discs because sometimes one may not work on a given computer system.
And I’m not bashing the Linux distros available. It is possibly an unfair comparison for me to critique a Linux CD for not having a current Windows program. The current version of DEFT (5.1 unless I am missing v6 somewhere) has FTK Imager 2.6, which is several versions below 3.0. This is not a complaint of the DEFT developers as when I use DEFT (yes, I do), I use the bootable side, not the Windows side. I do not see running a Windows app, like FTK Imager in a Linux environment, when I can run it is a bootable Windows environment.
My point with WinFE and software tools is that when a forensic software is released (such as FTK Imager 3.0), you can add it to WinFE the same day you download it. You do not have to wait for the developers of a Linux disc to update their distro before its available online. Again, FTK Imager is a poor choice to compare, probably a more fair comparison would be to compare a Linux app that has been upgraded but not yet added to a Linux CD.
If you look at the page I have with other booting options, you’ll see that I recommend at least having some or many options to boot a computer forensically. It wasn’t an untruth when I said not all distros are updated regularly. Although DEFT has been updated since 2005, SPADA hasn’t been updated since 2005. It was a general statement, not meant to offend.