Does anyone know where I can get hold of a version of ewfacquire for Windows. Need to keep disk space to a minimum and use command line in Windows FE. Trying to see if I can image Shadow Files with ewfacquire.
Where have you seen a reference to ewfacquire for Windows?
I haven't, just wondered if someone was smart enough to port it over. Still don't understand why such a tool isn't produced by Guidance.
Have you tried compiling it under Cygwin?
Get it at http//
The beta-version compiles flawlessly with Visual Studio 2008. No need for Cygwin anymore.
I haven't, just wondered if someone was smart enough to port it over. Still don't understand why such a tool isn't produced by Guidance.
I'm confused, surely that's EnCase (with or without the dongle).
Rich,
The library provides the ability to read the EWF format, most often associated with EnCase. However, FTK Imager and now ProDiscover include the ability as well.
The fact is that ewflib is NOT EnCase. Ewflib does not provide a GUI interface nor an EnScript scripting capability.
Greetings,
You took Rich's comment out of context. Someone asked why "such a tool isn't produced by Guidance."
The ewfacquire man page says "ewfacquire is a utility to acquire media data from a source and store it in EWF format (Expert Witness Compression Format). ".
EnCase, without the dongle, provides that capability, thus prompting, I presume, Rich's comment. In other words, that tool is provided by Guidance and it is called "EnCase" which, without the dongle, runs in Acquisition mode only, providing the same functionality as ewfacquire though without command line support.
-David
Harlan,
I just meant that why would Guidance spend time (ie money) to port ewfacquire, when they already produce the ability to image (even without a dongle) in windows. (and they're flogging their portable edition etc for other stuff)
Rich
Edit (you beat me to this reply David) 😉
Get it at http//
sourceforge.net/projects/libewf/ The beta-version compiles flawlessly with Visual Studio 2008. No need for Cygwin anymore.
Except that you have to pay for Visual Studio twisted