digitalsleuth / WIN-FOR

Windows Forensics Environment Builder
https://digitalsleuth.gitbook.io/win-for-documentation/
MIT License
106 stars 18 forks source link
forensics forensics-investigations forensics-tools windows

Win-FOR

Windows Forensics (Win-FOR) Customizer

GitHub release (with filter)

The design behind this is to use a barebones Windows 10 VM or a Windows machine (preferably 1909 and higher to support WSLv2). Once configured, and activated (to support customization features), then you can use one of the installers to install all of the packages.

The installer is a graphical interface to click and choose which items you want, and to enter the settings you need

Check out the Releases section for the most up-to-date installers.

Win-FOR Customizer

FIRST OFF - Requires .NET 6.0 Desktop Runtime If you do not have it, you will be prompted to install at execution

Why a GUI? Who doesn't like a good GUI!? Not everyone enjoys Windows command line or PowerShell, especially when just starting out in Digital Forensics. This makes it much easier to get your environment set up without having to worry about CMD or PS!

The customizer tool gives you the following features:

screenshot-v8 4 0

screenshot-options-v8 4 0

PowerShell or CLI

The PowerShell script and standalone CLI executable have been deprecated in favour of the Win-FOR Customizer.
However, if there is need for a command-line version of the Customizer, it can be done. Until such time, the Customizer is your best choice!

Issues

All issues should be raised here