Forensic Acquisition Guide

70 acquisition methods across 5 platforms. Step-by-step guidance for preserving and collecting forensic evidence.

Physical Acquisition17

FTK Imager
EnCase Forensic
dd (Windows port)dc3dd
Guymager
dddc3dd
dcfldd
ewfacquire (libewf)
Guymager
dddc3ddForensic boot USB
Target Disk ModeFTK Imagerdd
Apple Configurator 2USB-C cable
Hot air rework stationeMMC/UFS chip readerBGA reballing kit
JTAG adapter (Riff Box, EASY-JTAG, Medusa Pro)Soldering equipment
ISP adapter (EASY-JTAG, Medusa Pro)Soldering equipment
Qualcomm EDL toolsEASY-JTAGCellebrite UFED
Cellebrite UFEDGrayKeyBelkasoft Xcheckra1n
GrayKey

Logical Acquisition15

FTK Imager
tarsha256sum
rsyncsha256sum
SUMURI Recon ITR
Cellebrite Digital Collector
ADB (Android Debug Bridge)
ADBRoot access (Magisk/SuperSU)
Cellebrite UFEDCellebrite Physical Analyzer
MSAB XRYXAMN (analysis)
Oxygen Forensic Detective
iTunesFinder (macOS)iBackupBotiExplorer
libimobiledeviceiFunBoxiMazing
Cellebrite UFEDBelkasoft XElcomsoft iOS Forensic Toolkit
Cellebrite UFEDCellebrite Physical Analyzer
Elcomsoft iOS Forensic Toolkit

Memory Acquisition7

WinPmem
DumpIt (Comae)
Magnet RAM Capture
Belkasoft RAM Capturer
LiME
AVML
ddgdb

Triage Acquisition12

KAPE
Velociraptor
CyLR
Velociraptor
UAC
CyLR
AutoMacTC
mac_apt
Mac-TriageBash
MVT
AndroidQF
iOS SettingsFinder/iTunessysdiagnose parser

Remote Acquisition7

Velociraptor
Magnet AXIOM Cyber
GRR Rapid Response
Velociraptor
ddSSHdc3dd
Magnet AXIOM Cyber
Velociraptor

Cloud Acquisition7

AWS CLIAWS Console
Azure CLIAzure Portal
AWS CLIAWS Console
gcloud CLIGCP Console
Elcomsoft Phone BreakeriCloud WebLegal Process
Google TakeoutElcomsoft Cloud ExplorerLegal Process
Elcomsoft Phone BreakerCellebrite CloudLegal Process

VM Acquisition2

vSphere ClientESXi CLISCP/SFTP
Hyper-V ManagerPowerShell

Container Acquisition3

Docker CLI
Docker CLI
kubectlcrictlCRI-O