Creating Windows USB for DFIR & Fun (DRAFT)

I was researching a quick way to create a windows based live usb for forensics when I came across this article:

Windows 10 PE for Digital Forensics

This article was great and help so I wanted to summarize it and add somethings I noticed along the way.

Getting Started

What is Windows PE?

Windows PE (WinPE) for Windows 10 is a small operating system used to install, deploy, and repair Windows 10 for desktop editions (Home, Pro, Enterprise, and Education), Windows Server, and other Windows operating systems. From Windows PE, you will have the ability to:

  • Set up your hard drive before installing Windows.
  • Install Windows by using apps or scripts from a network or a local drive.
  • Capture and apply Windows images.
  • Modify the Windows operating system while it’s not running.
  • Set up automatic recovery tools.
  • Recover data from unbootable devices.
  • Add your own custom shell or GUI to automate these kinds of tasks.

To begin setting up our Windows USB we will need a copy of Windows Assessment & Deployment Kit (ADk)

Written on December 1, 2019