<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Windows Forensic Environment</title>
	<atom:link href="http://winfe.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://winfe.wordpress.com</link>
	<description></description>
	<lastBuildDate>Wed, 04 Jan 2012 02:07:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='winfe.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Windows Forensic Environment</title>
		<link>http://winfe.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://winfe.wordpress.com/osd.xml" title="Windows Forensic Environment" />
	<atom:link rel='hub' href='http://winfe.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Building your WinFE Update</title>
		<link>http://winfe.wordpress.com/2012/01/03/building-your-winfe-update/</link>
		<comments>http://winfe.wordpress.com/2012/01/03/building-your-winfe-update/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 02:07:51 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[batch files]]></category>
		<category><![CDATA[forensic work]]></category>
		<category><![CDATA[open source tools]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=595</guid>
		<description><![CDATA[For those that have been using WinFE and wanting to know about recent updates, I have only a little news to mention.    WinFE is still just as good today as when Troy Larson first created it, so not much &#8230; <a href="http://winfe.wordpress.com/2012/01/03/building-your-winfe-update/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=595&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For those that have been using WinFE and wanting to know about recent updates, I have only a little news to mention.    WinFE is still just as good today as when Troy Larson first created it, so not much in the update area there.  WinFE still boots the same computer systems and you can do the same forensic work as before, not much has changed since then.  <a href="http://support.microsoft.com/kb/300415" target="_blank"> DiskPart</a> is still the primary (only) method to toggle drives on/offline, which isn&#8217;t difficult to do.  Still command line, but easy commands to use.</p>
<h2>WinFE Batch File Building Method</h2>
<p>And building WinFE is the same as before, no changes there either.  If you use the batch file method, you can write your own or you can download pre-made batch files using the Box.net widget on this site to the right.   Several to choose and modify to suit your preferences.</p>
<p>The location of the batch files on this blog looks like the below screenshot, so if you don&#8217;t see it, you may need to have Java enabled in your browser.</p>
<div id="attachment_596" class="wp-caption alignright" style="width: 310px"><a href="http://winfe.files.wordpress.com/2012/01/batch.png"><img class="size-medium wp-image-596" title="batch" src="http://winfe.files.wordpress.com/2012/01/batch.png?w=300&#038;h=241" alt="" width="300" height="241" /></a><p class="wp-caption-text">All the batch files are in this zip file.</p></div>
<h2>WinFE WinBuilder Building Method</h2>
<p>If you are using WinBuilder (<a href="www.reboot.pro" target="_blank">www.reboot.pro</a>), there have been a continual update of the WinFE scripts by RoyM.  The reboot.pro site is also the best place for forum support directly with the script writers if you have problems building your WinFE.  RoyM (and others) has taken a great lead in the WinFE WinBuilder development.  My hat is off to all the contributors.</p>
<h2>Other Forensic Boot Systems</h2>
<p>The &#8220;other&#8221; forensic boot systems have had a few updates, some major.  I would highly recommend checking out <a href="http://forwarddiscovery.com/Raptor" target="_blank">Raptor</a>, <a href="http://www.caine-live.net/" target="_blank">CAINE</a>, and <a href="http://www.deftlinux.net/" target="_blank">DEFT</a>!  A major difference between WinFE and several of the Linux forensic boot systems is that many of the Linux systems are pre-made forensic OS&#8217;s, with freeware/open source tools already installed.  WinFE requires you to add the apps you want to use, which may be freeware, open source, or commercial.    A more complete forensic G0-Bag Kit has all of them&#8230;.just in case&#8230;.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/595/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=595&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2012/01/03/building-your-winfe-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2012/01/batch.png?w=300" medium="image">
			<media:title type="html">batch</media:title>
		</media:content>
	</item>
		<item>
		<title>An update to a long awaited project</title>
		<link>http://winfe.wordpress.com/2011/09/27/an-update-to-a-long-awaited-project/</link>
		<comments>http://winfe.wordpress.com/2011/09/27/an-update-to-a-long-awaited-project/#comments</comments>
		<pubDate>Wed, 28 Sep 2011 02:59:45 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=588</guid>
		<description><![CDATA[It&#8217;s been awhile, a long while, since there has been anything added to the WinFE project, and the bad news is that nothing is new other than Microsoft not quite accepting of Colin Ramsden&#8217;s write protect tool.   As that &#8230; <a href="http://winfe.wordpress.com/2011/09/27/an-update-to-a-long-awaited-project/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=588&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been awhile, a long while, since there has been anything added to the WinFE project, and the bad news is that nothing is new other than Microsoft not quite accepting of Colin Ramsden&#8217;s write protect tool.   As that is not good news, both Troy and Colin are working toward an effort that may meet Microsoft&#8217;s needs for an acceptable (to Microsoft&#8230;) write protect application other than DiskPart.</p>
<p>Sorry for the news on no news, but WinFE still works as it is, you just need to use the command line to toggle drives on/offline.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/588/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=588&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/09/27/an-update-to-a-long-awaited-project/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>
	</item>
		<item>
		<title>Sharing the love with WinFE</title>
		<link>http://winfe.wordpress.com/2011/05/09/sharing-the-love-with-winfe/</link>
		<comments>http://winfe.wordpress.com/2011/05/09/sharing-the-love-with-winfe/#comments</comments>
		<pubDate>Mon, 09 May 2011 21:49:04 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=566</guid>
		<description><![CDATA[There have been numerous presentations showing how to build and use a WinFE boot disc around the world.  Most recently I see that IACIS has given a demo this year along with several HTCIA Chapters and a DOD conference as well. &#8230; <a href="http://winfe.wordpress.com/2011/05/09/sharing-the-love-with-winfe/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=566&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There have been numerous presentations showing how to build and use a WinFE boot disc around the world.  Most recently I see that IACIS has given a demo this year along with several HTCIA Chapters and a DOD conference as well.  A write up of <a href="http://katanaforensics.com/2011/05/imaging-a-macbook-air/" target="_blank">Imaging a MacBook</a> by Sean Morrissey shows just how easy WinFE is to use on a MacBook based on one demo at IACIS.<a href="http://winfe.files.wordpress.com/2011/05/apple-macbook-pro.jpg"><img class="alignright size-thumbnail wp-image-568" title="apple-macbook-pro" src="http://winfe.files.wordpress.com/2011/05/apple-macbook-pro.jpg?w=150&#038;h=130" alt="" width="150" height="130" /></a></p>
<p>As simple as it is to use, it has become even easier to build using <a href="http://reboot.pro" target="_blank">WinBuilder</a>.  Probably the most significant difference when using WinBuilder rather than building via WAIK and the command line is the numerous options that can be automatically added, particularly in that of supporting more software able to run on WinFE.</p>
<p><img class="size-medium wp-image-570 alignleft" title="WinBuilder" src="http://winfe.files.wordpress.com/2011/05/winbuilder.png?w=300&#038;h=195" alt="" width="300" height="195" /></p>
<p>Many examiners have already tried to build and use WinFE, but I know there are a few of you out there that just haven&#8217;t sat down to give it a whirl.   If you can speak to anyone that uses WinFE, they will each tell you that it is well worth it!</p>
<p>The next coolest thing to be added to WinFE is Colin Ramsden&#8217;s GUI currently being finalized.   Say goodbye to the DiskPart command line!</p>
<p><a href="http://winfe.files.wordpress.com/2011/05/gui.jpg"><img class="alignright size-full wp-image-574" title="GUI" src="http://winfe.files.wordpress.com/2011/05/gui.jpg?w=640" alt=""   /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/566/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=566&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/05/09/sharing-the-love-with-winfe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/05/apple-macbook-pro.jpg?w=150" medium="image">
			<media:title type="html">apple-macbook-pro</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/05/winbuilder.png?w=300" medium="image">
			<media:title type="html">WinBuilder</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/05/gui.jpg" medium="image">
			<media:title type="html">GUI</media:title>
		</media:content>
	</item>
		<item>
		<title>Friendly reminders are always nice</title>
		<link>http://winfe.wordpress.com/2011/04/24/friendly-reminders-are-always-nice/</link>
		<comments>http://winfe.wordpress.com/2011/04/24/friendly-reminders-are-always-nice/#comments</comments>
		<pubDate>Sun, 24 Apr 2011 18:32:45 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=555</guid>
		<description><![CDATA[Always test your tools (this includes WinFE).  Considering that NIST recently discovered that some Ubuntu based forensic boot discs could make modifications to a booted suspect drive (modifies the $logfile upon booting&#8230;.),  these sort of news breaks are a friendly reminder &#8230; <a href="http://winfe.wordpress.com/2011/04/24/friendly-reminders-are-always-nice/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=555&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Always test your tools (this includes WinFE).  Considering that <a href="http://www.nist.gov/" target="_blank">NIST </a>recently discovered that some Ubuntu based forensic boot discs could make modifications to a booted suspect drive (modifies the $logfile upon booting&#8230;.),  these sort of news breaks are a friendly reminder to test your tools.  Additionally, when &#8216;bugs&#8217; are found in forensic tools, it may help to review any cases that may be affected by a past use of a tool.  Even Guidance Software just released a <a href="http://app.go.guidancesoftware.com/e/er.aspx?s=1413&amp;lid=559&amp;elq=9ae99cc616fe48f39288eb0690bacf83" target="_blank">firmware update</a> to a <strong>hardware</strong> physical write blocker in which writes to the evidence drive were not protected.  How&#8217;s that for reassurance with hardware write blockers being known as the absolute write protection tool?</p>
<p>You can&#8217;t rely upon someone else&#8217;s work, you can&#8217;t even rely upon the label of a box of something you buy.  You just have to spend the time to test it personally.</p>
<p>If you&#8217;ve not tested a tool that you used and later find that there was a problem with it, how long will you worry about one of those times you relied upon it to come back to haunt you in a past case?</p>
<p>Better that you tested it (&#8220;<em>I know it works because I tested it</em>&#8220;) rather than rely on someone else to test it (&#8220;<em>But the company/website/brochure said it worked.</em>..&#8221;). <a href="http://winfe.files.wordpress.com/2011/04/cartoon.jpg"><img class="alignright size-full wp-image-556" title="cartoon" src="http://winfe.files.wordpress.com/2011/04/cartoon.jpg?w=640" alt=""   /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/555/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=555&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/04/24/friendly-reminders-are-always-nice/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/04/cartoon.jpg" medium="image">
			<media:title type="html">cartoon</media:title>
		</media:content>
	</item>
		<item>
		<title>How easy (or difficult) is it to build a WinFE with WinBuilder?</title>
		<link>http://winfe.wordpress.com/2011/04/13/how-easy-or-difficult-is-it-to-build-a-winfe-with-winbuilder/</link>
		<comments>http://winfe.wordpress.com/2011/04/13/how-easy-or-difficult-is-it-to-build-a-winfe-with-winbuilder/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 18:48:46 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=532</guid>
		<description><![CDATA[An easy quickstart guide to build your WinFE ISO&#8230; 1) Extract WinBuilder to the root of your C:/ drive 2) Run WinBuilder 3) Click 3 buttons and you are done. If you want more features, such as additional programs, network &#8230; <a href="http://winfe.wordpress.com/2011/04/13/how-easy-or-difficult-is-it-to-build-a-winfe-with-winbuilder/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=532&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2 style="text-align:center;"><strong>An easy quickstart guide to build your WinFE ISO&#8230;</strong></h2>
<p>1) <strong>Extract </strong>WinBuilder to the root of your C:/ drive</p>
<p>2) <strong>Run </strong>WinBuilder</p>
<p>3) <strong>Click <em>3</em> buttons</strong> and you are done.</p>
<p>If you want more features, such as additional programs, network support, audio, more drivers, customized wallpaper, create a bootable WinFE flashdrive, etc&#8230;, then you just need to push a few more buttons.  Download and read the write up (<a href="http://winfe.files.wordpress.com/2011/01/users-guide-to-winfe1.pdf">Users Guide to WinFE</a>) for details on adding features.  It&#8217;s just as easy as pushing the 3 buttons.</p>
<p>These screenshots show all that is needed.  <strong><em>Now, after looking at what is needed to create your WinFE, what is the reason you haven&#8217;t started yet?&#8230;..</em></strong></p>
<p><a href="http://winfe.files.wordpress.com/2011/04/one1.jpg"><img class="size-full wp-image-544 alignleft" title="one" src="http://winfe.files.wordpress.com/2011/04/one1.jpg?w=640" alt=""   /></a><img class="size-full wp-image-534 alignleft" title="two" src="http://winfe.files.wordpress.com/2011/04/two.jpg?w=640" alt=""   /><img class="alignright size-full wp-image-535" title="three" src="http://winfe.files.wordpress.com/2011/04/three.jpg?w=640&#038;h=453" alt="" width="640" height="453" /><img class="alignright size-full wp-image-536" title="four" src="http://winfe.files.wordpress.com/2011/04/four.jpg?w=640&#038;h=455" alt="" width="640" height="455" /><img class="alignright size-full wp-image-537" title="five" src="http://winfe.files.wordpress.com/2011/04/five.jpg?w=640&#038;h=190" alt="" width="640" height="190" /></p>
<p>﻿﻿</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/532/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=532&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/04/13/how-easy-or-difficult-is-it-to-build-a-winfe-with-winbuilder/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/04/one1.jpg" medium="image">
			<media:title type="html">one</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/04/two.jpg" medium="image">
			<media:title type="html">two</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/04/three.jpg" medium="image">
			<media:title type="html">three</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/04/four.jpg" medium="image">
			<media:title type="html">four</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/04/five.jpg" medium="image">
			<media:title type="html">five</media:title>
		</media:content>
	</item>
		<item>
		<title>Triage Notes and WinFE</title>
		<link>http://winfe.wordpress.com/2011/03/02/triage-notes-and-winfe/</link>
		<comments>http://winfe.wordpress.com/2011/03/02/triage-notes-and-winfe/#comments</comments>
		<pubDate>Wed, 02 Mar 2011 20:05:53 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=484</guid>
		<description><![CDATA[One of the biggest benefits (besides imaging storage media) of WinFE is the ability to create a customized triage system at virtually no cost.  Purchasing a pre-made system may not be an issue when only one or a few systems &#8230; <a href="http://winfe.wordpress.com/2011/03/02/triage-notes-and-winfe/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=484&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the biggest benefits (besides imaging storage media) of WinFE is the ability to create a customized triage system at <strong>virtually no cost</strong>.  Purchasing a pre-made system may not be an issue when only one or a few systems are needed, but when outfitting an entire unit or perhaps an entire police department, bulk purchases of software to be issued individually most likely may not happen.  Completing disregarding the ability to triage due to cost does not benefit the community or country.  Finding solutions does.</p>
<p>With a WinFE &#8220;triage system&#8221;, the cost can be minimal due to the multitude of freely available software available.  Not to be confused with shareware, pirated software, or other questionable software, there are plenty available at no cost that are effective and easy to use (and did I mention the keyword &#8220;<strong>free</strong>&#8220;?).</p>
<p>So, when contemplating purchasing a pre-built system, consider that a customized system can be simply created <strong>that fits the needs and budget of your organization or your case</strong>.</p>
<p>There are several tools of worthy mention, but plenty more that are just as viable for triage and forensic quality software.</p>
<p>For law enforcement and military, there is the excellent (and free!) search tool &#8220;<a href="http://www.justnet.org/Pages/fieldsearch.asp" target="_blank">Field Search</a>&#8220;.  Field Search is a tool initially developed to <strong>run on a live machine</strong> to scan for images, internet history, and other items of evidential value.</p>
<p><img class="size-full wp-image-500 alignright" title="FS" src="http://winfe.files.wordpress.com/2011/03/fs.jpg?w=640" alt=""   /></p>
<p><strong>Field Search can also run under a WinFE booted system</strong>, giving it the capability of being &#8220;forensic&#8221; in that instead of running on the suspect machine and altering the system, it can now be run without altering the system.   Field Search is an extremely quick and easy program to use for First Responders and those in combat zones.  The use of this program in a forensic environment just doubled its potential.</p>
<p>The only limits to the software that will run on WinFE are those that depend upon the dependent files.  As an example, the Microsoft .NET framework is needed to run <strong>ChromeAnalysis</strong> and <strong>FoxAnalysis</strong>.   .NET is installed in the WinFE with the check of a box when using WinBuilder to build a WinFE ISO.  With that,  both FoxAnalysis and ChromeAnalysis from <a href="http://forensic-software.co.uk/" target="_blank">www.forensic-software.co.uk</a> run in the WinFE booted system giving more options in triage.  Both of these tools provide an intensive internet history capability in any forensic examination, and can be easily used in a triage/preview situation.  <span style="font-family:Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;font-size:13px;line-height:19px;"><img class="size-thumbnail wp-image-499" title="Chrome" src="http://winfe.files.wordpress.com/2011/03/chrome.png?w=108&#038;h=26" alt="" width="108" height="26" /></span></p>
<p style="text-align:left;">Other types of forensic software can also be used to target specifically desired information.  <a href="http://www.regripper.net" target="_blank">RegRipper</a> can be used to run against an entire drive and output specific results to a text file.  RegRipper (freely available!) can be modified in a multitude to ways to target what may be needed in a given scenario, either by using pre-made plugins or writing a unique plugin based on what is needed.<a href="http://www.regripper.net"><img class="alignright size-thumbnail wp-image-508" title="RR" src="http://winfe.files.wordpress.com/2011/03/rr.png?w=150&#038;h=44" alt="" width="150" height="44" /></a></p>
<p style="text-align:left;"><strong>WinFE allows you to customize a triage booting system based on several factors</strong> other than just a budget.  As an example, a police department can have a WinFE customized for First Responders with a bare minimal selection of triage tools, Field Search being a prime example.   Investigators could have additional tools (with some additional training) that can go beyond the First Responders&#8217; needs.  <img class="aligncenter size-thumbnail wp-image-504" title="triage" src="http://winfe.files.wordpress.com/2011/03/triage.png?w=150&#038;h=76" alt="" width="150" height="76" />With this type of system, by the time a forensic examiner is given evidence to examine, the evidence has been prioritized by the First Responder and case investigator to best determine how resources should be spent.  Compared to literally dumping multiple computers onto an examiner&#8217;s desk and asking for &#8220;everything&#8221;, triage can be conducted for more effective results and quicker turnaround.  <strong>This can be applied to non-LE work as well. </strong></p>
<p style="text-align:left;">Since <strong>WinFE can boot virtually any intel based computer</strong>, (this also includes Macs and *nix machines), the majority of situations can be handled with it.   Forensic Linux boot discs can be used in the same fashion as WinFE, using Linux software, however, I would hazard a guess to opin that most computer users are using the Windows Operating System.  Giving an unfamiliar operating system to a First Responder may be creating a problem due to mistakes being made by not knowing &#8216;which buttons to push&#8217; to find the evidence&#8230;Those with more experience with Linux should not have that problem.  Given the option to outfit a battalion of combat troops with this capability&#8230;I&#8217;d probably lean heavily toward a Windows based system&#8230;</p>
<p>Fairly soon, if not already in some jurisdictions, the days of giving the forensic examiner dozens of hard drives that have not been previewed or triaged in some fashion by someone, will be over.   A WinFE triage system can be configured to find basic information (user accounts, internet history, graphics, etc&#8230;) which can be used to prioritize, or even eliminate, media to be examined.  Some information that can be gleaned onsite during triage could <strong>substantially affect the outcome of the situation</strong> (combat arena?  searching for victims related to an electronic crime scene? or other scenarios where an extensive examination will yield results that may be useless months later?).</p>
<p>Using a triage system can save more hours than you may initially realize.  If just one computer hard drive is triaged, and determined not to be of importance (as compared to the other 10 in the investigation&#8230;), then it need not be imaged (saving hours) and need not be examined (saving days).  <strong> It&#8217;s very easy to determine the ROI or manhours saved with one hard drive</strong>, extrapolate that to dozens or more hard drives.  How&#8217;s that for cutting down the workload?</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/484/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/484/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/484/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/484/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/484/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/484/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/484/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/484/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=484&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/03/02/triage-notes-and-winfe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/03/fs.jpg" medium="image">
			<media:title type="html">FS</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/03/chrome.png?w=150" medium="image">
			<media:title type="html">Chrome</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/03/rr.png?w=150" medium="image">
			<media:title type="html">RR</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/03/triage.png?w=150" medium="image">
			<media:title type="html">triage</media:title>
		</media:content>
	</item>
		<item>
		<title>OSForensics</title>
		<link>http://winfe.wordpress.com/2011/02/28/osforensics/</link>
		<comments>http://winfe.wordpress.com/2011/02/28/osforensics/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 21:17:17 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=485</guid>
		<description><![CDATA[Giving more usability to WinFE, OSForensics has several features that I can see being beneficial in triage of a system with OSForensics.  OSForensics can be run on a live system (not the optimal decision in most cases), a mounted image, &#8230; <a href="http://winfe.wordpress.com/2011/02/28/osforensics/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=485&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Giving more usability to WinFE, OSForensics has several features that I can see being beneficial in triage of a system with <a href="http://www.osforensics.com/index.html" target="_blank">OSForensics</a>.  OSForensics can be run on a live system (not the optimal decision in most cases), a mounted image, or in a forensically booted WinFE system.</p>
<p><a href="http://www.osforensics.com/"><img class="size-full wp-image-486 alignright" title="osf-logo" src="http://winfe.files.wordpress.com/2011/02/osf-logo.png?w=640" alt=""   /></a></p>
<p>The program&#8217;s interface is simple and encompasses quite a bit of the basic forensic processes (searching, indexing, hashing, etc&#8230;).  Of particular interest is that some of these standard forensic processes can easily be used in a WinFE booted system for basic triage.</p>
<p>As an example, a scan of images of the suspect computer can be conducted with OSForensics.    This type of triage may certainly help determine which computer systems contain illicit images and need forensic analysis.<a href="http://winfe.files.wordpress.com/2011/02/screenshot-1.jpg"><img class="alignnone size-full wp-image-487" title="Triage" src="http://winfe.files.wordpress.com/2011/02/screenshot-1.jpg?w=640&#038;h=480" alt="" width="640" height="480" /></a></p>
<p>Another feature that can benefit cases is that of indexing.  OSForensics allows for indexing of files, including email (pst, mbox.msg,eml, and dbx), for keyword searches.    Searches can also be restricted by date ranges.</p>
<p>Although OSForensics doesn&#8217;t appear to be as powerful as a tool such as X-Ways Forensics, I definitely foresee a place where it can used, particularly in a First Responder role.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/485/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/485/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/485/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=485&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/02/28/osforensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/02/osf-logo.png" medium="image">
			<media:title type="html">osf-logo</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/02/screenshot-1.jpg" medium="image">
			<media:title type="html">Triage</media:title>
		</media:content>
	</item>
		<item>
		<title>WinFE Demo Online</title>
		<link>http://winfe.wordpress.com/2011/02/25/winfe-demo-online/</link>
		<comments>http://winfe.wordpress.com/2011/02/25/winfe-demo-online/#comments</comments>
		<pubDate>Sat, 26 Feb 2011 01:38:06 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=481</guid>
		<description><![CDATA[I&#8217;ll be giving a demo of WinFE to www.ctin.org on March 10 (online).  I&#8217;ll be showing some neat developments in the work as well as discuss solving build problems. There are a few spots left and you have to be &#8230; <a href="http://winfe.wordpress.com/2011/02/25/winfe-demo-online/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=481&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ll be giving a demo of WinFE to <a href="http://www.ctin.org" target="_blank">www.ctin.org</a> on March 10 (online).  I&#8217;ll be showing some neat developments in the work as well as discuss solving build problems.</p>
<p><a href="http://www.ctin.org" target="_blank"><img class="size-full wp-image-482 alignright" title="ctin" src="http://winfe.files.wordpress.com/2011/02/ctin.png?w=640" alt=""   /></a></p>
<p><a href="http://www.ctin.org" target="_blank"></a>There are a few spots left and you have to be a CTIN member to view the presentation.  But maybe it is something worthwhile to join anyway as most all the training is free to members.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/481/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/481/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/481/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=481&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/02/25/winfe-demo-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/02/ctin.png" medium="image">
			<media:title type="html">ctin</media:title>
		</media:content>
	</item>
		<item>
		<title>But does it do Mac?</title>
		<link>http://winfe.wordpress.com/2011/02/15/but-does-it-do-mac/</link>
		<comments>http://winfe.wordpress.com/2011/02/15/but-does-it-do-mac/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 02:00:32 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=468</guid>
		<description><![CDATA[Just to clear up any questions on whether WinFE can &#8216;do a Mac&#8217;, well&#8230;it can.  And Linux too.  And of course it can do Windows as well.   As long as the machine can be booted to a WinFE CD or &#8230; <a href="http://winfe.wordpress.com/2011/02/15/but-does-it-do-mac/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=468&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-469 aligncenter" title="OS" src="http://winfe.files.wordpress.com/2011/02/os.jpg?w=640" alt=""   /></p>
<p>Just to clear up any questions on whether WinFE can &#8216;do a Mac&#8217;, well&#8230;it can.  And Linux too.  And of course it can do Windows as well.   As long as the machine can be booted to a WinFE CD or USB, then you can image the hard drive.  Actually, you can do a whole lot more than just image it&#8230;you can triage it, preview it, search it, or just copy files and folders from it.  If the drive is encrypted and you have the key, you can access the drive.  And what about VSS (Volume Shadow Service/Copies)&#8230;.you can access those too, all through WinFE.</p>
<p>I can promise that as soon as you build a WinFE CD or bootable USB, you will regret not having done it months or years earlier (it&#8217;s been around since 2008&#8230;.).  And if building a forensic boot OS makes you hesitate at all, there is no need because if you use <a href="http://winbuilder.net/downloads/WinFE_Builder.zip">WinBuilder</a>, it is as simple as pointing and clicking to fully customize your Windows FE CD or bootable USB.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/468/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=468&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/02/15/but-does-it-do-mac/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/02/os.jpg" medium="image">
			<media:title type="html">OS</media:title>
		</media:content>
	</item>
		<item>
		<title>It&#8217;s time to build your WinFE!</title>
		<link>http://winfe.wordpress.com/2011/01/15/its-time-to-build-your-winfe/</link>
		<comments>http://winfe.wordpress.com/2011/01/15/its-time-to-build-your-winfe/#comments</comments>
		<pubDate>Sat, 15 Jan 2011 22:45:33 +0000</pubDate>
		<dc:creator>Brett Shavers</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://winfe.wordpress.com/?p=431</guid>
		<description><![CDATA[You can now download the WinFE WinBuilder.  Thanks to everyone that helped support this effort, it was well worth it. Before you put this off any longer, download the WinFE WinBuilder and try out the Windows Forensic Environment.  As to &#8230; <a href="http://winfe.wordpress.com/2011/01/15/its-time-to-build-your-winfe/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=431&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You can now download the WinFE WinBuilder.  Thanks to everyone that helped support this effort, it was well worth it.</p>
<p><a href="http://winfe.files.wordpress.com/2011/01/screenshot-10.jpg"><img class="alignnone size-full wp-image-434" title="WinFE Desktop" src="http://winfe.files.wordpress.com/2011/01/screenshot-10.jpg?w=640&#038;h=480" alt="" width="640" height="480" /></a></p>
<p><a href="http://winfe.files.wordpress.com/2011/01/screenshot-10.jpg"></a>Before you put this off any longer, download the <a href="http://winbuilder.net/downloads/WinFE_Builder.zip"><strong>WinFE WinBuilder </strong></a>and try out the Windows Forensic Environment.  As to a guide on how to use WinFE, it probably isn&#8217;t really needed since <em>WinFE is simply a forensic boot disc</em>.  So, you might not need any help in putting WinFE to good use.  However&#8230;there may be a few things you didn&#8217;t know you could do with WinFE that could be of interest.   Since that might be the case, here is a quick guide on tips on using WinFE as well as tips for building with WinBuilder.</p>
<p><a href="http://winfe.files.wordpress.com/2011/01/users-guide-to-winfe1.pdf">Users Guide to WinFE</a></p>
<p>For support on how to use WinBuilder (troubleshooting, advanced features), check out the WinBuilder website at <a href="http://reboot.pro" target="_blank">http://reboot.pro</a>.</p>
<p>To reiterate some points about WinFE (and to hopefully prevent &#8216;hate mail&#8217; coming to me from commercial products&#8230;), WinFE is an <strong>addition</strong> to your forensic toolkit. It doesn&#8217;t replace any tools, only supplements what you are using anyway.   Commercial products that do the same thing that WinFE does work too, keep buying those if you want, you don&#8217;t have to use WinFE.  And for the Linux lovers out there (Hey, I&#8217;m one of you guys too!), there is time and place for everything, sometimes WinFE is best, another time CAINE or DEFT or ???*nix may be best.</p>
<p>As far as anyone making a profit out of WinFE, no need to ask, because no one is;  it is a community project of customizing a Windows PE to fit your needs.</p>
<p>And yes, there are even some more neat things to be added to WinFE in the future&#8230;but as of now, you have access to a solid forensic environment.</p>
<p>For additional credits to this project;</p>
<div><em><strong>This project uses the project Win7PE_SE as Base building, thank&#8217;s to ChrisR for his great work ( Win7PE_SE <a href="http://reboot.pro/12427/" target="_blank">http://reboot.pro/12427/</a>).  Also, thanks to theYahoouk , JFX, Altorian, Lancelot, and RuiPaz with the Win7PE project on which this WinFE WinBuilder is based.</strong></em></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/winfe.wordpress.com/431/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/winfe.wordpress.com/431/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/winfe.wordpress.com/431/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/winfe.wordpress.com/431/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/winfe.wordpress.com/431/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/winfe.wordpress.com/431/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/winfe.wordpress.com/431/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/winfe.wordpress.com/431/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=winfe.wordpress.com&amp;blog=14271781&amp;post=431&amp;subd=winfe&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://winfe.wordpress.com/2011/01/15/its-time-to-build-your-winfe/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3c59396b7623ac6680768bdcaf7f20db?s=96&#38;d=monsterid&#38;r=R" medium="image">
			<media:title type="html">winfe</media:title>
		</media:content>

		<media:content url="http://winfe.files.wordpress.com/2011/01/screenshot-10.jpg" medium="image">
			<media:title type="html">WinFE Desktop</media:title>
		</media:content>
	</item>
	</channel>
</rss>
