Acquire ewf images with ewfacquire on MacOSX/Freebsd/OpenBSD/Linux

Besides reading and writing (EnCase) EWF files with the libewf library, it’s now possible to read and write SMART images as well. With the ewfacquire tool you now can create a bit-copy image from devices in the SMART image format (s01). The ewfacquire tool supports reading devices in Linux, FreeBSD, NetBSD, OpenBSD, MacOS-X/Darwin. On other platforms (Windows/Cygwin) it can convert a raw (dd) image into a EWF file or SMART file. With the tool you can acquire disk images just like in Encase or FTK and save the same meta data and hash value within the EWF or SMART file.

Usage ewfacquire:
./ewfacquire /dev/hda

The libewf library is integrated within the Sleuth Kit and so are the other tools. The libewf library comes with other tools to export data from EWF or SMART files (ewfexport), show the meta data stored in the EWF or SMART file (ewfinfo), and verify the integrity of the EWF or SMART files (ewfverify)

You can download the source code on the project website:

https://www.uitwisselplatform.nl/projects/libewf/


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

Leave a Comment

Latest Videos

Digital Forensics News Round Up, March 27 2024 #dfir #digitalforensics

Forensic Focus 24 hours ago

Digital Forensics News Round-Up, March 21 2024 #digitalforensics #dfir

Forensic Focus 21st March 2024 6:15 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feeds settings page to add an API key after following these instructions.

Latest Articles