Here are some screenshots of Colin’s work in progress. Click on the images for a closer look of the features. Nicely done Colin, I look forward to your finished product. For everyone waiting, as soon as available, Colin’s work will be here for your use. What more could you ask for?
Login
-
Recent Comments
NV on For those that still haven… Jeff Ellis on Colin’s Write Protect… Brett Shavers on Colin Ramsden’s Wor…
SANS- "The APT is already in your network. Time to go hunting -- Learn how in new training course SANS FOR508"
- "Digital Forensics and Incident Response Summit 26-27 June in Austin Texas"
- "Digital Forensic Case Leads : Flame On! The most sophisticated malware since...the last one, Higher Ed data breach and PowerShell forensics."
Windows Incident Response
RegRipper
Computer Forensics and IR
Grand Stream Dreams-
Blog Stats
- 91,372 hits







Oh My..I drool in anticipation.. These may be the Break out tools needed for the FE project..
Nice work!
Hold on a bit longer as Colin’s tweaks to WinFE get finalized. A few more issues to work out and it’ll be posted here.
Hi there,
WinFe is a really nice project. Thank you very much for this
Do you know if the Gui of Colin Ramsden will be available soon? Thank you very much
Alexandre
Colin’s app is being reviewed, tested, and approved for release presently. He is also adding a few more features during this time as well while it is being reviewed. Windows FE isn’t “new” anymore, but Colin’s application makes WinFE a real game changer for forensic boot discs. Issues of not being able to toggle flash/usb drives has been fixed, the command line for DiskPart has become irrelevant, and the ease to toggle drives makes it a simple process for first responders as well as forensic experts to image, preview, triage, and exam drives under WinFE.
The biggest benefit….easy to build, easy to customize, easy to use, and you only need your Windows install disc to build it.
Can Colin (or anybody) describe which executable during the boot process that does the signing (the 4 byte signature) on unsigned disks? Is it the kernel?
High,
A lot of us would like to use Colin Ramsden’s diskpart GUI for home use, outside of the forensic realm, so it actually would not matter if it’s 100 % conform to what Microsoft wants.
Isn’t there a way to upload Colin Ramsden’s gui for the people who don’t care about a few quirks
it may still have (for which we would take entire responsibility, so Colin could not be harassed for anything that would go wrong), so we can already use it now ?
Please could you already send it to me ?
Actually…unlike everyone else, I’d prefer to avoid the use of gui tools when it comes to forensics. I would like something like script to record everything I type manually (and output), instead of redirecting every thing (with time stamps) to a file. Now that would be ideal.
Is that completely dead by now?
What do you mean by dead?