<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WinPE 3.0 &amp; Forensics</title>
	<atom:link href="http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Tue, 07 Feb 2012 08:17:21 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: WinPE v3.0 &#8211; Platinum Tools &#171;</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-170036</link>
		<dc:creator>WinPE v3.0 &#8211; Platinum Tools &#171;</dc:creator>
		<pubDate>Mon, 06 Feb 2012 00:50:26 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-170036</guid>
		<description>&lt;p&gt;[...] answer has come from a this site, to edit the registry hive from regedit itself.  Here is how I have done it (thus [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] answer has come from a this site, to edit the registry hive from regedit itself.  Here is how I have done it (thus [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: AllAboutDataRec</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-21085</link>
		<dc:creator>AllAboutDataRec</dc:creator>
		<pubDate>Wed, 15 Dec 2010 12:00:16 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-21085</guid>
		<description>&lt;p&gt;Thanks. Definately going to try this.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks. Definately going to try this.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: ELDI</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-17351</link>
		<dc:creator>ELDI</dc:creator>
		<pubDate>Mon, 08 Nov 2010 20:31:51 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-17351</guid>
		<description>&lt;p&gt;I make this small program in java for use the Dism.exe present in Windows 7 with GUI or Visual Mode,&lt;/p&gt;

&lt;p&gt;Download Link:
GDism ELDI v2.2 Final:
mediafire : ?uvxd4dk6kuv9ian (...fire.com/?uvx...)
Commands you can use on GUI or Visual Mode:
* Mount-Wim
* Commit-Wim
* Unmount-Wim
* Get-WinInfo
* Get-MountedWinInfo
* CleanUp-Wim
* Get-Packages
* Add-Package
* Remove-Package
* Get-Drivers
* Get-DriverInfo
* Add-Driver
* Remove-Driver
* Make ISO
You must need the JRE installed (Java Runtime Enviroment).&lt;/p&gt;

&lt;p&gt;@ByELDI&lt;/p&gt;

&lt;p&gt;v2.2
Progress Bar
Time Counter&lt;/p&gt;

&lt;p&gt;v2.1
Fixed iso making
Menu translated
Button Cancel Process&lt;/p&gt;

&lt;p&gt;v2.0
Better Interface for results text
Make iso image with oscdimg
Support WAIK
Support x64
Better Config File
Size reduced&lt;/p&gt;

&lt;p&gt;v1.4
Fixed Process on wait list
Config File&lt;/p&gt;

&lt;p&gt;v1.3
Translate English-Espanol
Multiples Process Waiting&lt;/p&gt;

&lt;p&gt;v1.2
Fixed Drivers Functions&lt;/p&gt;

&lt;p&gt;http://www.mediafire.com/?uvxd4dk6kuv9ian&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I make this small program in java for use the Dism.exe present in Windows 7 with GUI or Visual Mode,</p>

<p>Download Link:
GDism ELDI v2.2 Final:
mediafire : ?uvxd4dk6kuv9ian (&#8230;fire.com/?uvx&#8230;)
Commands you can use on GUI or Visual Mode:
* Mount-Wim
* Commit-Wim
* Unmount-Wim
* Get-WinInfo
* Get-MountedWinInfo
* CleanUp-Wim
* Get-Packages
* Add-Package
* Remove-Package
* Get-Drivers
* Get-DriverInfo
* Add-Driver
* Remove-Driver
* Make ISO
You must need the JRE installed (Java Runtime Enviroment).</p>

<p>@ByELDI</p>

<p>v2.2
Progress Bar
Time Counter</p>

<p>v2.1
Fixed iso making
Menu translated
Button Cancel Process</p>

<p>v2.0
Better Interface for results text
Make iso image with oscdimg
Support WAIK
Support x64
Better Config File
Size reduced</p>

<p>v1.4
Fixed Process on wait list
Config File</p>

<p>v1.3
Translate English-Espanol
Multiples Process Waiting</p>

<p>v1.2
Fixed Drivers Functions</p>

<p><a href="http://www.mediafire.com/?uvxd4dk6kuv9ian" rel="nofollow">http://www.mediafire.com/?uvxd4dk6kuv9ian</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: উইন্ডোজের পাসওয়ার্ড ভুললে করণীয় &#171; Computer Tips &#38; Tricks</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-13663</link>
		<dc:creator>উইন্ডোজের পাসওয়ার্ড ভুললে করণীয় &#171; Computer Tips &#38; Tricks</dc:creator>
		<pubDate>Sat, 04 Sep 2010 17:25:48 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-13663</guid>
		<description>&lt;p&gt;[...] WinPE 3.0 &amp; Forensics (praetorianprefect.com) [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] WinPE 3.0 &amp; Forensics (praetorianprefect.com) [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brett Shavers</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-11624</link>
		<dc:creator>Brett Shavers</dc:creator>
		<pubDate>Tue, 13 Jul 2010 15:26:21 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-11624</guid>
		<description>&lt;p&gt;You definitely started something (your wish has been granted...).&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You definitely started something (your wish has been granted&#8230;).</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Troy</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-11236</link>
		<dc:creator>Troy</dc:creator>
		<pubDate>Sat, 03 Jul 2010 03:06:16 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-11236</guid>
		<description>&lt;p&gt;Thanks.&lt;/p&gt;

&lt;p&gt;I have held off on publishing Windows FE 3 instructions while I was researching some differences in volume mounting behavior between Vista and Windows 7.  However, it was always my wish that the forensics community build on Windows FE--that is why I only put out the most basic instructions.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks.</p>

<p>I have held off on publishing Windows FE 3 instructions while I was researching some differences in volume mounting behavior between Vista and Windows 7.  However, it was always my wish that the forensics community build on Windows FE&#8211;that is why I only put out the most basic instructions.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brett Shavers</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-10146</link>
		<dc:creator>Brett Shavers</dc:creator>
		<pubDate>Sat, 29 May 2010 23:40:28 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-10146</guid>
		<description>&lt;p&gt;I&#039;ve received enough requests about WinFe and a batch file to put it online at; http://winfe.tk/
Feel free to use the information and download the batch file and notes as needed.  Most everyone that tried WinFE, says they won&#039;t use anything else ;)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I&#8217;ve received enough requests about WinFe and a batch file to put it online at; <a href="http://winfe.tk/" rel="nofollow">http://winfe.tk/</a>
Feel free to use the information and download the batch file and notes as needed.  Most everyone that tried WinFE, says they won&#8217;t use anything else ;)</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brett Shavers</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-9888</link>
		<dc:creator>Brett Shavers</dc:creator>
		<pubDate>Thu, 20 May 2010 01:55:07 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-9888</guid>
		<description>&lt;p&gt;The tools only need to be copied to the folder.  FTK Imager needs a dll file copied from your computer to the mounted wim image (instructions are on the writeup at:  http://www.forensicfocus.com/downloads/WinFE.pdf&lt;/p&gt;

&lt;p&gt;To make it easier for you, I can send you a shared folder link to download the batch file that does it all for you, from start to finish.  Just let me know which email address you&#039;d like the link (or anyone else that&#039;d like the batch file, send me your email, I&#039;ll send the link to you).  The batch file in the write up isn&#039;t as complete as the one I use now.&lt;/p&gt;

&lt;p&gt;Brett
bshavers@gmail.com&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The tools only need to be copied to the folder.  FTK Imager needs a dll file copied from your computer to the mounted wim image (instructions are on the writeup at:  <a href="http://www.forensicfocus.com/downloads/WinFE.pdf" rel="nofollow">http://www.forensicfocus.com/downloads/WinFE.pdf</a></p>

<p>To make it easier for you, I can send you a shared folder link to download the batch file that does it all for you, from start to finish.  Just let me know which email address you&#8217;d like the link (or anyone else that&#8217;d like the batch file, send me your email, I&#8217;ll send the link to you).  The batch file in the write up isn&#8217;t as complete as the one I use now.</p>

<p>Brett
<a href="mailto:bshavers@gmail.com">bshavers@gmail.com</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-9842</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Mon, 17 May 2010 23:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-9842</guid>
		<description>&lt;p&gt;Brett,&lt;/p&gt;

&lt;p&gt;One thing I am missing is the concept of how to add tools to the &#92;Winfe folder. I would like to start with something simple like FTK Imager.&lt;/p&gt;

&lt;p&gt;Can you help or provide some direction? I would really like to try this as proof as concept before jumping ship to WINE.&lt;/p&gt;

&lt;p&gt;Thanks!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Brett,</p>

<p>One thing I am missing is the concept of how to add tools to the &#92;Winfe folder. I would like to start with something simple like FTK Imager.</p>

<p>Can you help or provide some direction? I would really like to try this as proof as concept before jumping ship to WINE.</p>

<p>Thanks!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brett Shavers</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-9358</link>
		<dc:creator>Brett Shavers</dc:creator>
		<pubDate>Sat, 01 May 2010 19:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-9358</guid>
		<description>&lt;p&gt;And my email...
bshavers@gmail.com&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>And my email&#8230;
<a href="mailto:bshavers@gmail.com">bshavers@gmail.com</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brett Shavers</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-9357</link>
		<dc:creator>Brett Shavers</dc:creator>
		<pubDate>Sat, 01 May 2010 19:53:32 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-9357</guid>
		<description>&lt;p&gt;A potential cause could be that the files were copied onto the other .wim file.  I send you a batch file that automates the entire process (send me an email so I know where to share the file).  I&#039;ve not had any problems using the batch file I wrote, you are free to use it.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>A potential cause could be that the files were copied onto the other .wim file.  I send you a batch file that automates the entire process (send me an email so I know where to share the file).  I&#8217;ve not had any problems using the batch file I wrote, you are free to use it.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Howard Patterson</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-9260</link>
		<dc:creator>Howard Patterson</dc:creator>
		<pubDate>Wed, 28 Apr 2010 18:25:19 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-9260</guid>
		<description>&lt;p&gt;When I have attempted this, using both a Vista SP1 and Win7 machine, the resultant iso won&#039;t boot properly and doesn&#039;t contain the tools I copied to the mount directory. I have used both the imagex and dism methods, and both fail.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>When I have attempted this, using both a Vista SP1 and Win7 machine, the resultant iso won&#8217;t boot properly and doesn&#8217;t contain the tools I copied to the mount directory. I have used both the imagex and dism methods, and both fail.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Week 15 in Review &#8211; 2010 &#124; Infosec Events</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-8965</link>
		<dc:creator>Week 15 in Review &#8211; 2010 &#124; Infosec Events</dc:creator>
		<pubDate>Tue, 20 Apr 2010 03:54:14 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-8965</guid>
		<description>&lt;p&gt;[...] WinPE 3.0 &amp; Forensics &#8211; praetorianprefect.com You may find this analysis interesting if you are a Windows expert performing a forensics analysis. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] WinPE 3.0 &amp; Forensics &#8211; praetorianprefect.com You may find this analysis interesting if you are a Windows expert performing a forensics analysis. [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Price</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-8881</link>
		<dc:creator>Simon Price</dc:creator>
		<pubDate>Fri, 16 Apr 2010 15:40:55 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-8881</guid>
		<description>&lt;p&gt;Thanks Brett, I updated the post to include the link to the PDF, very nice document.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks Brett, I updated the post to include the link to the PDF, very nice document.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brett Shavers</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/comment-page-1/#comment-8880</link>
		<dc:creator>Brett Shavers</dc:creator>
		<pubDate>Fri, 16 Apr 2010 14:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608#comment-8880</guid>
		<description>&lt;p&gt;Nice write up on WinFE.  Regarding the comment of this being too hard, I have a similar paper on WinFE that details a sample batch file that automates nearly the entire process.
http://www.forensicfocus.com/downloads/WinFE.pdf&lt;/p&gt;

&lt;p&gt;And its good to see that Windows FE is finally getting the attention I believe it deserves as a tool in the forensic toolbox.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice write up on WinFE.  Regarding the comment of this being too hard, I have a similar paper on WinFE that details a sample batch file that automates nearly the entire process.
<a href="http://www.forensicfocus.com/downloads/WinFE.pdf" rel="nofollow">http://www.forensicfocus.com/downloads/WinFE.pdf</a></p>

<p>And its good to see that Windows FE is finally getting the attention I believe it deserves as a tool in the forensic toolbox.</p>]]></content:encoded>
	</item>
</channel>
</rss>

