Forensic Acquisition Guide
70 acquisition methods across 5 platforms. Step-by-step guidance for preserving and collecting forensic evidence.
Physical Acquisition17
FTK Imager
EnCase Forensic
dd (Windows port)dc3dd
Guymager
dddc3dd
dcfldd
ewfacquire (libewf)
Guymager
dddc3ddForensic boot USB
Target Disk ModeFTK Imagerdd
Apple Configurator 2USB-C cable
Hot air rework stationeMMC/UFS chip readerBGA reballing kit
JTAG adapter (Riff Box, EASY-JTAG, Medusa Pro)Soldering equipment
ISP adapter (EASY-JTAG, Medusa Pro)Soldering equipment
Qualcomm EDL toolsEASY-JTAGCellebrite UFED
Cellebrite UFEDGrayKeyBelkasoft Xcheckra1n
GrayKey
Logical Acquisition15
FTK Imager
tarsha256sum
rsyncsha256sum
SUMURI Recon ITR
Cellebrite Digital Collector
ADB (Android Debug Bridge)
ADBRoot access (Magisk/SuperSU)
Cellebrite UFEDCellebrite Physical Analyzer
MSAB XRYXAMN (analysis)
Oxygen Forensic Detective
iTunesFinder (macOS)iBackupBotiExplorer
libimobiledeviceiFunBoxiMazing
Cellebrite UFEDBelkasoft XElcomsoft iOS Forensic Toolkit
Cellebrite UFEDCellebrite Physical Analyzer
Elcomsoft iOS Forensic Toolkit
Memory Acquisition7
WinPmem
DumpIt (Comae)
Magnet RAM Capture
Belkasoft RAM Capturer
LiME
AVML
ddgdb
Triage Acquisition12
KAPE
Velociraptor
CyLR
Velociraptor
UAC
CyLR
AutoMacTC
mac_apt
Mac-TriageBash
MVT
AndroidQF
iOS SettingsFinder/iTunessysdiagnose parser
Remote Acquisition7
Velociraptor
Magnet AXIOM Cyber
GRR Rapid Response
Velociraptor
ddSSHdc3dd
Magnet AXIOM Cyber
Velociraptor
Cloud Acquisition7
AWS CLIAWS Console
Azure CLIAzure Portal
AWS CLIAWS Console
gcloud CLIGCP Console
Elcomsoft Phone BreakeriCloud WebLegal Process
Google TakeoutElcomsoft Cloud ExplorerLegal Process
Elcomsoft Phone BreakerCellebrite CloudLegal Process
VM Acquisition2
vSphere ClientESXi CLISCP/SFTP
Hyper-V ManagerPowerShell
Container Acquisition3
Docker CLI
Docker CLI
kubectlcrictlCRI-O