Ewfacquire acquires disk images faster than with EnCase LiNen. The ewftool ‘ewfacquire’ has been profiled and also been optimized. From test on the same hardware the ewfacquire tool was in most tests significantly faster than EnCase LiNen 5.04. Especially when compression was used LiNen was outperformed. The ewfacquire tool can also be used to swap byte order, comparable to the dd swab conversion. This allows to swap between big and little endian conversion, which is a useful feature for examining media from certain appliances like Digital Video Recorders…Projects using libewf
In the last year several projects have start using libewf to provide for EWF support. Some of these are The SleuthKit, CarvFS, AFFlib, TestDisk and PhotoRec.
Libewf In-file (in-place) carving with PhotoRec
Libewf has been integrated into PhotoRec. PhotoRec by Christophe Grenier is currently one of the most advanced file carvers which supports carving from a lot of different file types. New and great functionality has been added to PhotoRec. It now offers in-place file carving. This means that the PhotoRec carver is file system- and EWF file aware and can directly access the unallocated space on a file system in EWF files. Currently PhotoRec 6.7 supports FAT16/FAT32 and NTFS file systems.
We would like to thank the contributors for their support.
We would to thank David Loveall for creating the mount-ewf tool. With this new application it’s possible to mount the media data in EWF files forensically as read-only devices. This allows you to access partitions directly as devices. Mount-ewf is depended on Fuse.
We would to thank Dennis Schreiber for creating the pyewf tool
Pyewf is a wrapper ‘gui’ script around the ‘ewfacquirestream’ tool. It allows you the create multiple images in batch with additional logging.
The libewf project can be found at:
Joachim Metz and Robert-Jan Mora from Hoffmann Investigations, Almere, The Netherlands