Portable Internet Evidence Finder and WinFE

Jad Saliba (of JadSoftware.com) has released an update to his Internet Evidence Finder/IEF in a portable version.  Now this sounds really good to have the ability to plug in a USB drive into a running machine to gather the information that IEF does.   But, to take it a step further, I tried IEF within a booted WinFE system.   And the result….it works perfectly!

To make sure you can get the full grasp of how neat this is, you can boot to WinFE and run IEF across the physical drive, without making any changes to the evidence.  This could be of real importance in an investigation such as a missing person case where internet/chat/webmail may be of immediate intelligence value.  Rather than imaging the hard drive to search for this data from the image, or booting the machine to its operating system and potentially overwriting pertinent data, you can boot to WinFE and run IEF on the write protected drive.   Of course, in a missing person case where chat is involved, it may also be most important to capture the volatile data FIRST before turning off the computer.

In civil case matters, this can be a fairly quick method of obtaining data relevant to the case matter onsite if imaging the hard drive is not allowed.

Although IEF doesn’t run on Mac or Linux….if you boot a Mac or Linux machine with WinFE, IEF will run against that Mac or Linux hard drive ;)

Advertisement

About Brett Shavers

http://winfe.wordpress.com
This entry was posted in Uncategorized. Bookmark the permalink.

2 Responses to Portable Internet Evidence Finder and WinFE

  1. Nily says:

    I am currently using a mac right now and was just wondering if i could get some info on how to boot a mac with WinFE.

    i am currently a college student and have lost some relevant information in my previous email service.

    thank you very much.

  2. Just boot the Mac to a WinFE CD. As long as it an intel Mac, it’ll boot to WinFE.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s