WinFE has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
WinFE (Windows Forensic Environment) is a community project, run in
collaboration with Arsenal Recon, for building a forensically sound
Windows PE-based boot environment — useful specifically when a case
calls for Windows-native tools (or hardware/driver support Linux-based
forensic distros like CAINE or SIFT don’t have) without booting the
suspect drive’s own installed OS.
Use it only against systems/media you own or are explicitly authorized
to examine — see the disclaimer.
Getting started
Unlike this catalog's other forensic distros, WinFE isn't a
ready-made downloadable ISO — it's built from a licensed Windows
installation/ADK using scripts and guidance published on the official
blog and winfe.net, since redistributing a modified Windows image
isn't legally possible the way a Linux respin is. The resulting boot
environment mounts local disks read-only by default (registry writes
disabled) so an examiner can run Windows-native forensic and
imaging tools against a system without altering evidence.
Before you continue
SecArsenal is an independent, educational reference. It does not host, distribute, or provide exploit code — only descriptions of, and links to, publicly available third-party tools and operating systems.
By continuing, you acknowledge that you will only use the tools and techniques referenced on this site against systems, networks, or accounts you own or are explicitly authorized to test; that unauthorized access to computer systems may be illegal in your jurisdiction; and that all information is provided "as is," and that SecArsenal and its contributors assume no liability for how it is used.
These change how this site looks and behaves in your browser only. Nothing is sent anywhere — your choices are saved on this device.
Larger text
Increases text size across the site by ~20%.
Extra spacing
Looser line, letter, and paragraph spacing in article text.
High contrast
Brighter muted text and borders, no decorative textures.
Always underline links
Identifies links by more than color alone.
Strong focus outline
A thicker, higher-contrast outline for keyboard navigation.
Reduce motion
Turns off hover/focus transitions, regardless of OS settings.
These toggles are a first-party enhancement layered on top of markup we build to follow WCAG 2.2 Level AA guidance — they are not a substitute for accessible design, and we have not undergone a formal third-party compliance audit, so we don't claim full conformance. If you hit a real accessibility barrier anywhere on this site, please open an issue — we'd rather hear about it than have this panel stand in for fixing it.