Educause Security Discussion mailing list archives

BartPE configuration and Plugin Vetting


From: "James H. Moore" <jhmiso () RIT EDU>
Date: Fri, 27 May 2011 10:14:31 -0400

I am thinking of changing my quotes to just "No New Wheels", i.e. I don't have time to start everything from scratch.

I am working on a BartPE disk for sysadmins/first responders.  I have questions about what your sysadmins use.  Is 
anyone willing to share what their BartPE configurations are (i.e. what is in their plugins and drivers directories), 
and if you have any particular documentation to go with it.

I started looking at some of the additional plugins that seemed to be well liked, and I was also wondering if anyone 
had bothered to vet them.

XPE - Sherpya WinPe Stuff http://oss.netfarm.it/winpe/ http://sourceforge.net/projects/winpe/
RunScanner (and other utilities) http://www.paraglidernc.com/winbuilder/default.htm
IronGeeks information - http://www.irongeek.com/i.php?page=security/pebuildertutorial
Ross Smith - http://smithii.com/files/plugins/  (including the Cygwin plugin - I would love to have grep available from 
BartPE)

Jim
- - - -
Jim Moore, CISSP, IAM
Senior Information Security Forensic Investigator Rochester Institute of Technology
151 Lomb Memorial Drive
Rochester, NY 14623-5603
(585) 475-5406 (office)
(585) 255-0809 (Cell - Incident Reporting & Emergencies)
(585) 475-7920 (fax)


If you consciously try to thwart opponents, you are already late.  Miyamoto Musashi, Japanese philosopher/samurai, 1645

A ship in harbor is safe -- but that is not what ships are built for.  John A. Shedd, Salt from My Attic, 1928 
CONFIDENTIALITY NOTE: The information transmitted, including attachments, is intended only for the person(s) or entity 
to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, 
dissemination or other use of, or taking of any action in reliance upon this information by persons or entities other 
than the intended recipient is prohibited. If you received this in error, please contact the sender and destroy any 
copies of this information


Current thread: