Windows Forensics (Win-FOR) Customizer
The design behind this is to use a barebones Windows VM or a Windows machine (preferably Windows 11 23H2 and higher to support WSLv2). Once configured, and activated (to support customization features), then you can use one of the installers to install all of the packages.
The installer is a graphical interface to click and choose which items you want, and to enter the settings you need
Check out the Releases section for the most up-to-date installers.
Why a GUI? Who doesn't like a good GUI!? Not everyone enjoys Windows command line or PowerShell, especially when just starting out in Digital Forensics. This makes it much easier to get your environment set up without having to worry about CMD or PS!
Win-FOR tool gives you the following features:
- Point and click to choose which tools you want installed in your distro (instead of just choosing them all)
- Checkboxes to choose if you want the WSLv2 with SIFT and REMnux, just SIFT, just REMnux, Kali, or all of them installed during the process, or click
WSL Onlyto install it at a later date. - Save your current selections in a custom SaltStack State file for your own purposes or record
- Identify the current version of the Win-FOR environment with a single click
- Check for updates to the Customizer
- Graphically enter any settings you need!
- In Win-FOR, select the apps and settings you want, check the "Offline" box under the Download button, then click Download.
- Visit the win-for-offline repo and download the latest release.
- Transfer your downloads and the win-for-offline installer to your offline machine.
- Launch the win-for-offline installer and select the path where your downloaded files are, where you want standalone applications to be placed, and the desired user
- Click Install!
All issues should be raised here


