Linux imaging tool ...
 
Notifications
Clear all

Linux imaging tool other than dd

40 Posts
21 Users
0 Reactions
3,729 Views
(@mattpenrose)
Eminent Member
Joined: 17 years ago
Posts: 28
Topic starter  

Hi
Does anyone know of any tools that can be installed on linux to acquire disk images other than dd?
Kind Regards
Matt


   
Quote
(@tomforman)
Eminent Member
Joined: 18 years ago
Posts: 29
 

Encase has Linen,
though i have to admit ive never used it


   
ReplyQuote
(@mholton)
New Member
Joined: 18 years ago
Posts: 2
 

Linen looks and feels the same as the old Encase DOS version.


   
ReplyQuote
ggrady
(@ggrady)
Active Member
Joined: 17 years ago
Posts: 6
 

There is also aimage

http//www.forensicswiki.org/wiki/Aimage


   
ReplyQuote
darren_q
(@darren_q)
Eminent Member
Joined: 20 years ago
Posts: 48
 

dcfldd - http//dcfldd.sourceforge.net/

Raptor has a great interface, but comes on a live cd - http//www.raptorforensics.com/Raptor_by_Forward_Discovery,_Inc..html

dd_rescue - http//www.garloff.de/kurt/linux/ddrescue/

sdd - http//directory.fsf.org/project/sdd/

AIR - http//www.l0t3k.org/security/tools/forensic/

sleuthkit - http//www.sleuthkit.org/

grab - http//digfor.blogspot.com/2008/09/grab-adepto.html

http//www.digitalforensics.ch/nikkel05b.pdf


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

Hi Matt,

There are many tools that can be used for acquiring, but the key ones in my experience are;

ddrescue (not underscore version, but GNU version)

SMART

dc3dd

aimage

ddrescue is superb in working with I/O error drives, and SMART has a simple, easy to use graphical user interface and unique capabilities in acquisition.

Cheers!

farmerdude

www.forensicbootcd.com

www.onlineforensictraining.com


   
ReplyQuote
(@mattpenrose)
Eminent Member
Joined: 17 years ago
Posts: 28
Topic starter  

excellent, thank you all for your input
Matt


   
ReplyQuote
(@de_ramon)
New Member
Joined: 17 years ago
Posts: 3
 

Hi,

the most importang / usefull one IMHO are the libewf based tools

http//guymager.sourceforge.net/

https://www.uitwisselplatform.nl/projects/libewf/

Because they are able to write EWF-Format, which is "standard".

Regards,

Ralf


   
ReplyQuote
(@corjoh)
New Member
Joined: 18 years ago
Posts: 1
 

You can actually "cat" hd's into an image file. I.e. # cat /dev/sda1 >> /mnt/usb1/diskimage.dd

It's a quick and dirty way of getting it done…

(just for informational purposes only)


   
ReplyQuote
(@larrydaniel)
Reputable Member
Joined: 17 years ago
Posts: 229
 

I am surprised no one mentioned FTK imager from Access Data.

I use linen quite a bit and it works well for me. Using it from the Helix 2009 R3 live disk.


   
ReplyQuote
Page 1 / 4
Share: