image

WinFE Course

I’m about halfway through the WinFE online course and then I’m sending it to a reviewer.  The topics and order of the curriculum are listed below. I’ve added a multitude of build methods that will be documented and demonstrated in the online class.  It’ll be recorded, so not a webinar where you have to close…

Some Interesting WinFE Related Stuff I Found Online

One of the interesting things I have found online related to WinFE as I create a lesson plan for WinFE is  “WTE” or “Windows Triage Environment”.  Before you get excited about this project, apparently, unless  you work in government, you can’t have it.  Per the website,  “WTE is released as freeware only for Law Enforcement or…

winfe2

Mini-WinFE Updated

“Misty” has updated Mini-WinFE, the quick and easy build of the Windows Forensic Environment.  There are some pretty neat updates to the build (listed below).  So far, the best documentation I have seen on WinFE, specifically Mini-WinFE is here: http://mistype.reboot.pro/documents/WinFE/winfe.htm. This is the kind of stuff you want to read in order to really know as…

winfe success

WinFE Success Story

I get a few stories of how WinFE saved the day and a few of these heroes let me retell their story. This is one of them. The ‘detective’ wishes to be unnamed, but for sake of argument, I know who he is… ————————————————————————————————————————  A detective from a California law enforcement agency that had attended…

fourth edition

Windows Forensic Analysis, Fourth Edition

I’ll wait to give an “official” review of Harlan’s book (Windows Forensic Analysis Toolkit, Fourth Edition: Advanced Analysis Techniques for Windows 8) only to give others the chance to read it once it becomes available.  But…I’ll say that based on my early reading as a tech editor, this is a book that ranks for me…

CyberCrime 2013 Symposium

I’m heading to New Hampshire (first time there) to present on Placing the Suspect Behind the Keyboard.   Sounds like a pretty good conference and certainly could not be any further for me to travel in the entire country.  Literally, from one end to the other.  Looking for to the conference, come say hello if…

Mini-WinFE

This is Project 1 of 3 for alternative WinFE builds.  The two other projects are forthcoming with the primary difference being you being able to choose which method you prefer. This build is tentatively called “Mini – WinFE” because it is a super quick method to build a WinFE with minimal features.  Primarily, it is…

Temporary 40% discount on a book I wrote

The X-Ways Practitioner Guide I wrote with Eric Zimmerman was just given a 40% discount from the publisher.   I am posting the information on the WinFE site mainly because X-Ways is the best forensic app that runs in WinFE, fully, without issues.   In the book, I give a few examples of using WinFE with XWF…

Making the build even easier

There are a few WinFE builders creating a standalone, push button build for WinFE based on WinBuilder.  It will be set for defaults selected for forensic soundness and include only that what is needed for WinFE.  The goal is a about as close to a ‘one-button build’ as possible.  All you will need is your…

Is WinFE still being used?

Yep!  Not only is WinFE still a viable project, it is being taught in more places, more often, to more people.  For example: The FAA: FAA78100041, (78100041) Creating a Windows FE DVD Search at the Child Abuse and Family Summit in Oregon. HTCIA at a training session in Washington (state). Another HTCIA here (with instructions to…