If you work in digital forensics or incident response, you know that your case starts with acquisition. And when you’re acquiring evidence from a forensically booted environment, you want something fast, court-defensible, and secure.
That’s where WinFE (Windows Forensic Environment) comes in, and now, for this week only, you can get formal training and certification for FREE.
🔗 Register Now:
👉 WinFE Certification Course
👉 Train-the-Trainer Course
📅 Offer expires May 14, 2025
🧰 Is WinFE still relevant?
Without the years of community use and support, WinFE may have remained a small, internal tool to a few select organizations… 😦
But WinFE has been taken well beyond that!
Unlike Linux-based forensic boot environments, WinFE supports full BitLocker access, a familiar Windows interface, and powerful forensic scripting, all while preventing writes to the evidence disk.
Arsernal Recon is pushing WinFE’s capabilities up a notch! So is Colin Ramsden (he is working on a huge update with cool features).
🎓 Two Free Courses — What You’ll Learn
✅ WinFE Certification
- What WinFE is and how it fits into forensic workflows
- Step-by-step build process using automated scripts
- Real-world applications and legal defensibility
- Instant, verifiable certificate upon completion
- Lifetime access, including the upcoming and updated WinFE training!
✅ WinFE Train-the-Trainer
- Everything from the certification course
- How to teach WinFE in an academic or agency setting
- Common student mistakes and how to troubleshoot
- Instructor-use content and build guidance
📦 Bonus: Both courses include a PowerShell script that builds a complete, functional WinFE automatically—no prior experience needed.
📈 Over 15,000 Trained — and Counting
Since I first began teaching WinFE, over 15,000 professionals have taken these courses—whether in a physical classroom, live online, or on-demand. My first online WinFE course had over 5,000 sign-ups way back when!
That number is incredible, especially when you consider that many DF/IR folks are using WinFE today without any formal training on WinFE—despite it being foundational to acquisitions. I’ll admit, it’s not a requirement or necessity to have training in WinFE to use, but I’ve seen tense moments in trial with an opposing expert struggled to explain his lack of training with WinFE other than having attended less than an hour at a conference.
This free training changes that. It’s not just about learning how to build a forensic boot disk—it’s about knowing how to defend your acquisition in court and ensure your case doesn’t fall apart because of a preventable mistake.
🧠 Why Training Matters
Let’s be real: your entire case depends on the integrity of your acquisition. WinFE gives you control, transparency, and reliability—but that’s not enough by itself.
If you’re ever cross-examined and asked:
“You booted the system with a forensic environment… but you didn’t take the free certification course available at the time?”
What do you say?
There’s no excuse. The course is free, fast, and backed by proven field use. Don’t leave your process open to scrutiny when you can shut that door completely—with a certificate to prove it.
🧠 Beyond Booting: Arsenal Recon’s AIM + WinFE
Want to take your workflow a step further?
Arsenal Recon’s Arsenal Image Mounter (AIM) lets you virtually boot the OS of the machine that you booted with WinFE. This enables:
- Live analysis of the user’s environment without altering evidence
- Remote access to booted systems for investigations
- Full interaction with encrypted or complex user environments
Pairing WinFE for acquisition with AIM for virtual booting creates an incredibly powerful, fully defensible workflow—ideal for both field work and lab analysis.
If you haven’t used AIM with your WinFE workflow yet, now is the time to explore what’s possible.
https://platform.twitter.com/widgets.jsFellow #DFIR practitioners – what do you see happening in this short video involving WinFE, AIM Remote Agent, & Arsenal Image Mounter? https://t.co/w8v2JqX7rn pic.twitter.com/GY68HmSX2y
— Arsenal Recon (@ArsenalRecon) May 11, 2025
🎁 Why It’s Free
This isn’t a gimmick—it’s a thank-you. These two courses normally cost a combined $220, but for two days only, I’m offering both for free as part of a push to make core forensic skills more accessible.
You’ll get:
- Full course access
- Downloadable build tools
- Certification of completion
- ebook
- Lifetime updates
- Powershell script that builds your entire WinFE, hands off.
⏳ Don’t Miss Out
The offer expires May 14, 2025. After that, both courses return to full price.
🔗 Register now:
👉 WinFE Certification
👉 Train-the-Trainer
Don’t put it off—this is your chance to lock in foundational forensic knowledge for free, defend your work in court, and join over 15,000 others who’ve taken WinFE training seriously.
See you in class,
Brett Shavers
www.DFIR.training
www.SuspectBehindTheKeyboard.com/mindset


