Bootable Windows environment for forensics - WinFE

Поделиться
HTML-код
  • Опубликовано: 30 июл 2024
  • Bootable Windows environment for forensics - WinFE
    ♥️ SUBSCRIBE for more videos: ruclips.net/user/bluemonkey4n6...
    Difficulty Level: Intermediate
    Prerequisites: basic understanding of digital forensics concepts.
    basic understanding of Windows command line
    In this video, we will look at the Windows Forensic Environment, otherwise known as WinFE. WinFE is a Microsoft Windows based forensic boot CD/DVD/USB/HDD. This is another external boot tool for your tool belt in addition to the usual Linux based boot drives.
    Video timeline
    00:00. intro
    01:10 downloading WinFE
    02:47 downloading forensic software
    04:48 building WinFE platform
    05:49 building bootable ISO for Ventoy
    06:22 building bootable USB
    09:20 boot to WinFE USB
    12:27 running WinFE
    14:22 imaging with FTK Imager
    🔨 Gear mentioned in this video:
    To more info on WinFE: www.winfe.net
    To download FTKImage: www.accessdata.com/product-do...
    See this website to see what the BootMenu key for your computer: www.disk-image.com/faq-bootmen...
    Brett Shavers conducts WinFE training (brettshavers.com) and has a book called Ultimate DFIR cheats! Windows Forensic Environment available on Amazon
    Icons made by freepik from @flaticon www.flaticon.com/authors/freepik
    Icons made by Smashicons from @flaticon www.flaticon.com/authors/smash...
    DISCLAIMER: Links in this video description might be affiliate links. If you purchase a product or service using one of these links, I may receive a small commission at no additional cost to you. Thank you!
    #DFIR #bootableUSB #bootableWindows
  • НаукаНаука

Комментарии • 30

  • @4n6wizard
    @4n6wizard Месяц назад +1

    Is a well know behavior that WinFE would write a 4 byte signature to any drive that doesn’t already have a 4 byte windows signature. So if you use WinFE on a Linux or Apple system it might write that 4 byte signature on the drive. Again, is a well documented behavior and easy to explain in court.

    • @BlueMonkey4n6
      @BlueMonkey4n6  Месяц назад +1

      Outstanding, thank you for chiming in.

  • @csanmarting
    @csanmarting 29 дней назад +1

    Excellent and useful video, congratulations from Chile.

    • @BlueMonkey4n6
      @BlueMonkey4n6  28 дней назад +1

      Hello Chile!🇨🇱. Thanks for watching and commenting!

  • @sykoteddy
    @sykoteddy Год назад +1

    I'm new to this but managed to build this bootable USB with Windows 10 Home 22H2 without any problems, except I had to use ".\MakeWinFEx64-x86" instead. I wonder if I implement OSForensics by installing it and copying it just like we did with FTKImage? Thanks in advance 👌

    • @BlueMonkey4n6
      @BlueMonkey4n6  Год назад

      Thanks for the comment about the WinFE link being broken. its now fixed. I'm not familiar with OSForensics on WinFE, let me know if you got it to work.

  • @aiakan
    @aiakan 2 месяца назад +1

    @BlueMonkey Is there a way to inject additional drivers into the WinFE build?? Particularly a cab file ? I need it to see Dell drives that use their software Raid option and it requires their RST driver to potentially work

    • @BlueMonkey4n6
      @BlueMonkey4n6  2 месяца назад

      I believe that if you add the cab file much like you would add forensic software before you build the platform, you should be good.

  • @caesare1968
    @caesare1968 Год назад +1

    EXCELLENT

    • @BlueMonkey4n6
      @BlueMonkey4n6  Год назад

      Thanks for the positive comment and thanks for watching

  • @LorenzoDeDonato
    @LorenzoDeDonato Месяц назад +1

    Hi, do you know why on mac mouse and keyboard don't work? I created the bootable stick with winfe, it starts but I can't advance because the mouse and keyboard don't work...

    • @BlueMonkey4n6
      @BlueMonkey4n6  Месяц назад

      oh, that's a very good question. I believe that you will need to install the drivers. See this article here: support.apple.com/guide/bootcamp-assistant/install-windows-newer-mac-boot-camp-bcmp173b3bf2/6.1/mac/14.0

  • @timjardim3483
    @timjardim3483 Год назад +1

    The version of WinFE I downloaded is missing the CAB Files for x86 and it is crashing the script. Any idea where to get these files?

    • @timjardim3483
      @timjardim3483 Год назад +1

      Most likely a Win 11 issues as the ADK does not support x86 anymore

    • @BlueMonkey4n6
      @BlueMonkey4n6  Год назад

      Try checking with the author to see if he’s working on Win11 updates

    • @colinramsden746
      @colinramsden746 10 месяцев назад +1

      @@BlueMonkey4n6 I'm currently too busy with work and other projects to do any further work on WinFE.

    • @BlueMonkey4n6
      @BlueMonkey4n6  10 месяцев назад +1

      Bummer, thank you for what you did so far.

  • @blackmarketcarrot1601
    @blackmarketcarrot1601 Год назад +1

    The winfe site doesnt seem to be up at least for me. Any other way to download this?

    • @BlueMonkey4n6
      @BlueMonkey4n6  Год назад +1

      Try github.com/bshavers/Mini-WinFE

    • @blackmarketcarrot1601
      @blackmarketcarrot1601 Год назад

      ​@@BlueMonkey4n6Seems to be blank with only a read me file, managed to grab it off waybackmachine. Thanks for the help.

  • @Sara-sv4ej
    @Sara-sv4ej 10 месяцев назад +1

    What if I only download one version of FTK imager of 64x , remain steps will be same or i will face an errors ?

    • @BlueMonkey4n6
      @BlueMonkey4n6  10 месяцев назад

      FTK Imager should run fine unless i am not understanding your question.

    • @Sara-sv4ej
      @Sara-sv4ej 10 месяцев назад +1

      @@BlueMonkey4n6 my question is : in the video , you downloaded two versions of FTK Imager I think 64x and 32x .. and I haven’t found the two version you downloaded, so can I download only the 64x version ?

    • @BlueMonkey4n6
      @BlueMonkey4n6  9 месяцев назад

      yes, most computers are 64 bit nowadays (instead of the old 32 bit) so the 64x version of FTK Imager should be fine.

  • @4n6wizard
    @4n6wizard 9 месяцев назад +1

    Great video thank you. How do I install other programs on WinFE?

    • @BlueMonkey4n6
      @BlueMonkey4n6  9 месяцев назад +1

      Basically you will need to install that program onto the windows computer that you are building WinFE on. Then drag the program folder within C:\Program Files(x86)\ to where I had the WinFE framework that is being built (Download\WinFE\USB\x86-x64\tools\x86). Then when you build WinFE, those programs will be part of your WinFE build. Refer to the 2:47 time mark of the video to watch this again.

    • @4n6wizard
      @4n6wizard 9 месяцев назад

      @@BlueMonkey4n6 thank you. I take from the video that I have to uninstall for example WinHex and install it again and then copy it and paste it in the WinFE USB tools folder.