The “Windows Forensic Environment” (aka WinFE or Windows FE) is the creation of Troy Larson (Microsoft). It is an operating system environment based from Microsoft PE (Preinstalled Environment), modified for forensic use.
WinFE forensically boots computers much like the various Linux forensics disks, however, WinFE is “Windows”, not Linux, thereby allowing the examiner to use Windows based forensic applications to image or examine suspect/custodian machines in a forensically sound environment.
Many of the improvements of WinFE have come from users. For a detailed write up (already outdated by many of the improvements submitted), click here: WinFE.
Brett Shavers
