daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

disk-imaging.md (18793B)


      1 ---
      2 title: "Disk & Memory Acquisition"
      3 description: "Forensically sound imaging on Linux and Windows: order of volatility, write blocking, dd/dc3dd/ewfacquire, FTK Imager, WinPmem/DumpIt/AVML/LiME memory capture, hashing, chain of custody and mounting images read-only for analysis."
      4 category: dfir
      5 subcategory: "Acquisition"
      6 tags: [dfir, forensics, acquisition, imaging, memory-forensics, chain-of-custody, e01, dd, windows, linux]
      7 tools: ["dd / dcfldd / dc3dd", "ewfacquire (libewf)", "FTK Imager", "Guymager", "WinPmem", "DumpIt", "AVML", "LiME", "ewfmount / xmount", "Arsenal Image Mounter"]
      8 difficulty: intermediate
      9 updated: "2026-09-26"
     10 ---
     11 
     12 # Disk & Memory Acquisition
     13 
     14 Everything downstream — timelines, registry parsing, carving, memory analysis — is only as good as the image it runs on. Acquisition is the one phase you cannot redo: a live box changes every second and a powered-off box loses its RAM forever. This card is the **order of operations**, the exact **`dd` / `ewfacquire` / FTK Imager** invocations, the **memory capture** tools per OS, and how to **hash, document and mount** the result so the analysis sheets ([EZ Tools](/sheets/dfir/ez-tools-kape), [Linux forensics](/sheets/dfir/linux-forensics), [Volatility](/sheets/dfir/volatility)) have something trustworthy to chew on.
     15 
     16 > [!warning] Two rules that never bend
     17 > 1. **Never write to the evidence.** Hardware write blocker on the suspect drive, or software blocking (`blockdev --setro`, Windows `diskpart` read-only attribute, FTK Imager's own protection) when you must go software-only.
     18 > 2. **Hash before, hash after, write it down.** An image without a matching acquisition hash is a file, not evidence.
     19 
     20 ## Order of volatility (RFC 3227)
     21 
     22 Collect what disappears fastest first. Every step below the line you are on is destroying evidence above it.
     23 
     24 | Priority | Evidence | Lifetime | Tool |
     25 |---|---|---|---|
     26 | 1 | Registers, CPU cache | nanoseconds | (not practically collectable) |
     27 | 2 | **RAM**, routing/ARP tables, process table, kernel state | until reboot | WinPmem, DumpIt, AVML, LiME |
     28 | 3 | Network connections, logged-in users, open files | seconds–minutes | `netstat`, `ss`, `w`, `lsof`, `Get-NetTCPConnection` |
     29 | 4 | Temp files, swap/pagefile, hiberfil | until overwritten | included in disk image; grab `pagefile.sys`/`hiberfil.sys` explicitly |
     30 | 5 | **Disk** | until overwritten | `dd`, `ewfacquire`, FTK Imager |
     31 | 6 | Remote logs, SIEM, backups | retention policy | export from source |
     32 | 7 | Physical configuration, topology | long | photos, notes |
     33 
     34 > [!tip] Pull the plug or shut down?
     35 > **Pull the plug** (hard power-off) preserves the disk as-is, including `hiberfil.sys`/`pagefile.sys`, and defeats shutdown-triggered anti-forensics. **Graceful shutdown** flushes caches and may fire a wiper. Default to: capture RAM live → pull the plug → image the disk. Exceptions: encrypted volumes you can only read while unlocked (image them **live**, or capture the key from RAM first), and servers where downtime is not yours to decide.
     36 
     37 ## Documentation & chain of custody
     38 
     39 Start the log before the first command. Every image needs:
     40 
     41 - Case ID, examiner, date/time (**with timezone** — record the suspect machine's clock skew against a reference clock too)
     42 - Device: make, model, serial, capacity, interface, physical condition, photos of labels
     43 - Acquisition method, tool + version, write-blocker used
     44 - **Source hash, image hash, verification result**
     45 - Every hand-off: who, when, why, signed
     46 
     47 ```bash
     48 # Capture the timestamp and clock skew at the very start
     49 date -u; hwclock -r 2>/dev/null      # on the suspect box (Linux)
     50 # Windows:
     51 # w32tm /stripchart /computer:pool.ntp.org /samples:3 /dataonly
     52 ```
     53 
     54 ## Live response (before you power off)
     55 
     56 Only do this when the RAM capture is done (or you cannot capture RAM). Run tools **from your own media**, redirect output to your own media, and know that every command you run leaves artefacts — log what you ran so the analyst (probably you) can exclude them later.
     57 
     58 ```bash
     59 # Linux — volatile state to an evidence mount
     60 E=/mnt/evidence/$(hostname)-$(date -u +%Y%m%dT%H%MZ); mkdir -p "$E"
     61 date -u                    > "$E/date.txt"
     62 uptime                     > "$E/uptime.txt"
     63 w; last -F                 > "$E/logins.txt"
     64 ps auxwwf                  > "$E/ps.txt"
     65 ss -tulpan                 > "$E/net.txt"
     66 ip a; ip r; arp -an        > "$E/ip.txt"
     67 lsof -nP                   > "$E/lsof.txt"
     68 mount; df -h               > "$E/mounts.txt"
     69 lsmod                      > "$E/lsmod.txt"
     70 cat /proc/mounts /proc/partitions > "$E/proc.txt"
     71 ```
     72 
     73 ```powershell
     74 # Windows — same idea, PowerShell (run from your USB, output to it)
     75 $E="E:\evidence\$env:COMPUTERNAME-$(Get-Date -f yyyyMMddTHHmm)"; mkdir $E | Out-Null
     76 Get-Date -Format o                              > "$E\date.txt"
     77 Get-Process -IncludeUserName | Sort StartTime   > "$E\ps.txt"
     78 Get-CimInstance Win32_Process | Select ProcessId,ParentProcessId,CommandLine | Export-Csv "$E\cmdlines.csv"
     79 Get-NetTCPConnection -State Established,Listen | Export-Csv "$E\net.csv"
     80 Get-NetNeighbor; Get-NetIPAddress; Get-DnsClientCache | Out-File "$E\netcfg.txt"
     81 query user; net session; net use               > "$E\sessions.txt"
     82 Get-ScheduledTask | Export-Csv "$E\tasks.csv"
     83 Get-Service | Export-Csv "$E\services.csv"
     84 Get-SmbOpenFile; Get-SmbSession               > "$E\smb.txt"
     85 ```
     86 
     87 ## Memory capture
     88 
     89 ### Windows
     90 
     91 | Tool | Notes | Command |
     92 |---|---|---|
     93 | **WinPmem** (Velocidex) | Open source, signed driver, raw or AFF4 output. The default choice. | `winpmem_mini_x64_rc2.exe C:\evidence\mem.raw` |
     94 | **DumpIt** (Magnet) | Single exe, one prompt, produces `.dmp` (Vol3 reads it). Good for junior responders. | `DumpIt.exe /OUTPUT E:\mem.dmp /QUIET` |
     95 | **Magnet RAM Capture** | GUI, free, handles Secure Boot / VSM boxes that stop other drivers | click Start |
     96 | **Belkasoft RAM Capturer** | GUI, free, low footprint | pick output dir, Capture |
     97 | **FTK Imager** | File → Capture Memory; can also grab `pagefile.sys` in the same pass | GUI |
     98 | **KAPE** | `--target MemoryFiles` collects hiberfil/pagefile/swapfile; use a `!SANS_Triage`-style target after RAM capture | see [EZ Tools](/sheets/dfir/ez-tools-kape) |
     99 
    100 ```powershell
    101 # WinPmem, raw image, then hash it
    102 .\winpmem_mini_x64_rc2.exe E:\evidence\mem.raw
    103 Get-FileHash E:\evidence\mem.raw -Algorithm SHA256 | Tee-Object E:\evidence\mem.raw.sha256
    104 
    105 # Also copy the swap/hibernation files for Volatility / Hibr2Bin
    106 # (locked while running — use FTK Imager's "Obtain Protected Files" or KAPE MemoryFiles)
    107 ```
    108 
    109 > [!info] Size and time
    110 > RAM image ≈ physical RAM (16 GB box → 16 GB file, 2–5 min over USB 3). Write to **external** media, never the suspect disk. If Volatility later fails to find symbols, capture `C:\Windows\System32\ntoskrnl.exe` too — Vol3 uses its PDB GUID to fetch the right symbol pack.
    111 
    112 ### Linux
    113 
    114 | Tool | Notes | Command |
    115 |---|---|---|
    116 | **AVML** (Microsoft) | Static binary, **no kernel module**, works on most kernels via `/proc/kcore` or `/dev/crash`. First choice. | `./avml mem.lime` |
    117 | **LiME** | Kernel module, must be built against the target's exact kernel headers. Output format Vol3 reads natively. | `insmod lime-$(uname -r).ko "path=/mnt/evidence/mem.lime format=lime"` |
    118 | **/proc/kcore** via `dd` | Last resort, huge, not a clean physical map | avoid |
    119 
    120 ```bash
    121 # AVML — compress on the fly to your evidence mount
    122 ./avml --compress /mnt/evidence/mem.lime.compressed
    123 # or plain
    124 ./avml /mnt/evidence/mem.lime && sha256sum /mnt/evidence/mem.lime > /mnt/evidence/mem.lime.sha256
    125 
    126 # LiME — build on a matching kernel, never on the suspect box if you can avoid it
    127 git clone https://github.com/504ensicsLabs/LiME && cd LiME/src && make
    128 sudo insmod ./lime-$(uname -r).ko "path=/mnt/evidence/mem.lime format=lime"
    129 sudo rmmod lime
    130 
    131 # For Volatility 3 you will need a symbol table for this kernel:
    132 #   dwarf2json linux --elf /usr/lib/debug/boot/vmlinux-$(uname -r) > $(uname -r).json
    133 ```
    134 
    135 > [!tip] macOS
    136 > Modern Apple silicon makes live RAM capture impractical without vendor tooling. Collect volatile state with `sysdiagnose`, `ps`, `lsof`, `nettop`, and unified logs (`log collect --output case.logarchive`), then image the disk from Recovery / target disk mode.
    137 
    138 ## Disk imaging
    139 
    140 ### Identify the device first (and do not mount it)
    141 
    142 ```bash
    143 lsblk -o NAME,SIZE,MODEL,SERIAL,TYPE,MOUNTPOINT,FSTYPE
    144 sudo fdisk -l /dev/sdb
    145 sudo smartctl -i /dev/sdb              # serial, firmware, power-on hours — into the log
    146 sudo hdparm -I /dev/sdb | head -20
    147 sudo blockdev --setro /dev/sdb         # software write-block if no hardware blocker
    148 sudo blockdev --getro /dev/sdb         # → 1
    149 # Stop the desktop from auto-mounting removable media before you plug in:
    150 # gsettings set org.gnome.desktop.media-handling automount false
    151 ```
    152 
    153 ```powershell
    154 # Windows — find the disk and make it read-only in diskpart (no hardware blocker)
    155 Get-Disk | ft Number,FriendlyName,SerialNumber,Size,PartitionStyle
    156 diskpart
    157 # DISKPART> select disk 2
    158 # DISKPART> attributes disk set readonly
    159 # DISKPART> attributes disk   (verify "Read-only: Yes")
    160 ```
    161 
    162 ### `dd` family (raw images)
    163 
    164 ```bash
    165 # Baseline hash of the source (slow, but the gold standard)
    166 sudo sha256sum /dev/sdb | tee /mnt/evidence/sdb.source.sha256
    167 
    168 # Plain dd — works everywhere, no progress, no error handling
    169 sudo dd if=/dev/sdb of=/mnt/evidence/sdb.dd bs=4M conv=noerror,sync status=progress
    170 
    171 # dcfldd — hashes while imaging, splits, verifies
    172 sudo dcfldd if=/dev/sdb of=/mnt/evidence/sdb.dd bs=4M \
    173      hash=sha256 hashlog=/mnt/evidence/sdb.dd.hash \
    174      conv=noerror,sync statusinterval=256
    175 
    176 # dc3dd — the DoD successor to dcfldd, best error handling, logs everything
    177 sudo dc3dd if=/dev/sdb of=/mnt/evidence/sdb.dd \
    178      hash=sha256 hash=md5 log=/mnt/evidence/sdb.dd.log \
    179      rec=on                       # keep going on bad sectors, zero-fill them
    180 
    181 # Split raw image into 2 GB chunks (FAT32 evidence drive, or just manageability)
    182 sudo dc3dd if=/dev/sdb ofs=/mnt/evidence/sdb.dd.000 ofsz=2G hash=sha256 log=sdb.log
    183 
    184 # Verify: image hash must equal source hash
    185 sha256sum /mnt/evidence/sdb.dd
    186 ```
    187 
    188 > [!warning] `conv=noerror,sync` matters
    189 > Without `noerror` a single bad sector aborts the image. Without `sync` the bad block is skipped instead of zero-padded, and **every offset after it shifts**, breaking filesystem parsing. Use both, and record the bad-sector list from the log.
    190 
    191 ### E01 / EWF (compressed, hashed, metadata-carrying)
    192 
    193 The Expert Witness Format is what commercial suites (EnCase, FTK, X-Ways) expect, compresses well, embeds the case notes and checksums every chunk. Prefer it over raw when the image will be shared.
    194 
    195 ```bash
    196 sudo apt install libewf-tools ewf-tools    # ewfacquire, ewfverify, ewfmount, ewfinfo
    197 
    198 # Interactive (asks for case number, examiner, notes, compression, segment size)
    199 sudo ewfacquire /dev/sdb
    200 
    201 # Unattended
    202 sudo ewfacquire -u -t /mnt/evidence/sdb -C CASE-042 -E 001 -e "DAEMON" \
    203      -D "Laptop SSD, Samsung 970, S/N ..." -N "Seized 2026-09-26 room 3" \
    204      -c best -S 4G -d sha256 -f encase6 /dev/sdb
    205 
    206 ewfinfo   /mnt/evidence/sdb.E01           # metadata + stored hashes
    207 ewfverify /mnt/evidence/sdb.E01           # recompute and compare
    208 ewfexport -t /mnt/evidence/sdb.raw /mnt/evidence/sdb.E01   # back to raw when a tool needs it
    209 ```
    210 
    211 ### Guymager (Linux GUI)
    212 
    213 Pre-installed on SIFT/Kali/Tsurugi. Right-click the device → **Acquire image** → pick `.dd` or `.E01`, fill case fields, tick **Calculate SHA-256** and **Verify image after acquisition**. It logs to a `.info` file next to the image. Fast, multithreaded, and the sanest option when a colleague has never used `dd`.
    214 
    215 ### FTK Imager (Windows GUI + CLI)
    216 
    217 The most common Windows imager. Free, runs from a USB ("FTK Imager Lite"), no install.
    218 
    219 **GUI:** File → **Create Disk Image** → Physical Drive → select the suspect disk → Add destination → choose **E01** (or Raw/dd) → fill Evidence Item Information → set fragment size (0 = single file) and compression (6 default) → tick **Verify images after they are created** → Start. The summary window at the end has the MD5/SHA1 — screenshot it and save the `.txt` log it writes next to the image.
    220 
    221 Other jobs FTK Imager does that nothing else free does as easily:
    222 
    223 | Task | Menu |
    224 |---|---|
    225 | Copy locked live files (`$MFT`, hives, `pagefile.sys`, `NTUSER.DAT`) from a running box | File → **Obtain Protected Files** → tick *Password recovery and all registry files* |
    226 | Export a folder tree from an image with timestamps intact | File → Add Evidence Item → browse → right-click → **Export Files** |
    227 | Mount an E01 as a drive letter | File → **Image Mounting** → Physical & Logical, Read-only → Mount |
    228 | Capture RAM | File → **Capture Memory** (tick *Include pagefile*) |
    229 | Custom content image (only the paths you list, still hashed E01) | File → Create Disk Image → **Contents of a Folder**, or add to Custom Content Sources |
    230 | View file slack, unallocated, and ADS | Evidence tree → `[unallocated space]`, hex pane bottom right |
    231 
    232 ```bat
    233 :: FTK Imager CLI (ftkimager.exe, separate download) — image with verification
    234 ftkimager.exe \\.\PhysicalDrive2 E:\evidence\pd2 --e01 --frag 4G --compress 6 ^
    235    --case-number CASE-042 --evidence-number 001 --examiner DAEMON ^
    236    --description "Dell laptop SSD" --verify
    237 
    238 :: List physical drives
    239 ftkimager.exe --list-drives
    240 ```
    241 
    242 ### Live imaging (encrypted / cannot power off)
    243 
    244 When BitLocker/LUKS/FileVault means a dead image is ciphertext, image the **logical, unlocked volume** while it is mounted, and accept that the image is not a perfect snapshot.
    245 
    246 ```bash
    247 # Linux LUKS — image the mapped device, not the raw partition
    248 sudo dc3dd if=/dev/mapper/luks-xxxx of=/mnt/evidence/root-decrypted.dd hash=sha256 log=root.log
    249 ```
    250 
    251 ```bat
    252 :: Windows BitLocker — logical drive letter, plus grab the recovery key while you can
    253 manage-bde -protectors -get C: > E:\evidence\bitlocker-keys.txt
    254 ftkimager.exe C: E:\evidence\C-logical --e01 --verify
    255 ```
    256 
    257 > [!tip] Cloud and virtual machines
    258 > VMs: snapshot, then copy the `.vmdk`/`.vhdx`/`.qcow2` and the `.vmem`/`.vmsn` (that *is* the memory image). `qemu-img convert -f vmdk -O raw disk.vmdk disk.raw` gets you something every tool reads. Cloud: snapshot the volume (AWS `create-snapshot`, Azure `az snapshot create`), attach to a forensic instance in the same region, image from there — do not download 500 GB over the internet.
    259 
    260 ## Hashing & verification
    261 
    262 ```bash
    263 # Multiple algorithms in one pass (GNU coreutils 9+ or via hashdeep)
    264 hashdeep -c md5,sha256 -e /mnt/evidence/sdb.dd > sdb.dd.hashes
    265 # Verify later against that file
    266 hashdeep -c md5,sha256 -a -k sdb.dd.hashes /mnt/evidence/sdb.dd
    267 
    268 # Hash a split image as one stream
    269 cat sdb.dd.0* | sha256sum
    270 
    271 # Hash every file inside a mounted image (for a known-good/bad comparison later)
    272 find /mnt/img -type f -exec sha256sum {} + > case-filehashes.txt
    273 ```
    274 
    275 ```powershell
    276 Get-FileHash E:\evidence\pd2.E01 -Algorithm SHA256
    277 certutil -hashfile E:\evidence\pd2.E01 SHA256          # no PowerShell needed
    278 ```
    279 
    280 > [!info] MD5 is fine here
    281 > MD5 collisions are a real cryptographic weakness but irrelevant to proving an image was not altered by accident. Courts and tools still use MD5+SHA1; adding SHA-256 costs nothing. Record all of them.
    282 
    283 ## Mounting images for analysis (read-only, always)
    284 
    285 ```bash
    286 # Raw image: find partition offsets, then mount one
    287 sudo mmls sdb.dd                       # Sleuth Kit: sector offsets of each partition
    288 sudo fdisk -l sdb.dd
    289 sudo mount -o ro,loop,noexec,noload,offset=$((2048*512)) sdb.dd /mnt/img     # ext4 (noload = don't replay journal)
    290 sudo mount -o ro,loop,noexec,show_sys_files,streams_interface=windows,offset=$((1050624*512)) sdb.dd /mnt/img   # NTFS via ntfs-3g, exposes $MFT and ADS
    291 # Whole disk as block devices
    292 sudo losetup -rfP --show sdb.dd        # → /dev/loop0, /dev/loop0p1, ... (-r read-only, -P scan partitions)
    293 sudo mount -o ro,noexec /dev/loop0p2 /mnt/img
    294 sudo losetup -d /dev/loop0
    295 
    296 # E01: expose as raw first
    297 sudo mkdir -p /mnt/ewf && sudo ewfmount sdb.E01 /mnt/ewf         # → /mnt/ewf/ewf1 (raw view)
    298 sudo losetup -rfP --show /mnt/ewf/ewf1
    299 # or xmount, which also fakes a writable overlay (cache file) so tools that insist on writing work
    300 sudo xmount --in ewf sdb.E01 --out raw --cache /tmp/sdb.cache /mnt/xm
    301 
    302 # LVM inside an image
    303 sudo losetup -rfP --show sdb.dd && sudo vgscan && sudo vgchange -ay && lsblk
    304 # Windows VSS shadow copies inside an NTFS image
    305 sudo vshadowinfo /dev/loop0p2 && sudo vshadowmount /dev/loop0p2 /mnt/vss && ls /mnt/vss   # vss1, vss2 ...
    306 ```
    307 
    308 ```powershell
    309 # Windows: Arsenal Image Mounter (free, handles E01/raw/VHD, true disk-level mount so
    310 # VSS and BitLocker-unlocked volumes behave). Mount → pick image → "Read only" → OK.
    311 # FTK Imager: File → Image Mounting → Mount Type "Physical & Logical", Mount Method "Block Device / Read Only".
    312 # Native for VHD/VHDX only:
    313 Mount-DiskImage -ImagePath E:\evidence\disk.vhdx -Access ReadOnly
    314 ```
    315 
    316 > [!warning] `ro` is not a write blocker
    317 > A read-only mount stops *you* writing; it does not stop a journaling filesystem replaying its journal on mount (hence `noload` on ext4), and it does not stop macOS Spotlight or Windows indexing from touching an image file you open in a GUI. Analyse **copies** of the image, keep the original hashed on a shelf.
    318 
    319 ## Quick decision table
    320 
    321 | Situation | Do |
    322 |---|---|
    323 | Running Windows workstation, suspected malware | RAM (WinPmem) → protected files (FTK Imager) → pull plug → E01 of disk |
    324 | Running Linux server, cannot reboot | AVML → live response script → `dc3dd` of `/dev/mapper/*` if encrypted, else schedule downtime for a dead image |
    325 | Powered-off laptop, unknown encryption | Do **not** boot it. Pull drive, hardware blocker, E01. Check `ewfinfo`/`mmls` for BitLocker signatures; hunt for recovery key in the user's cloud account or AD `msFVE-RecoveryInformation` |
    326 | USB stick / SD card | Blocker, `dc3dd`, then [carve](/sheets/dfir/strings-file-triage) — small media are mostly deleted files |
    327 | Phone | Different discipline entirely (Cellebrite/GrayKey/ALEAPP/iLEAPP); at minimum: airplane mode, Faraday bag, note lock state |
    328 | VM | Snapshot, copy `.vmdk` + `.vmem`, convert with `qemu-img` |
    329 
    330 ## Next steps
    331 
    332 - Windows image → [EZ Tools & KAPE](/sheets/dfir/ez-tools-kape) for parsing, [Digital Forensics reference](/sheets/dfir/forensics) for what to look for, [Registry (RECmd)](/sheets/dfir/recmd)
    333 - Linux image → [Linux forensics](/sheets/dfir/linux-forensics)
    334 - Memory image → [Volatility 3](/sheets/dfir/volatility)
    335 - Unknown files, unallocated space → [strings & file triage](/sheets/dfir/strings-file-triage)
    336 - Point-and-click review → [GUI tools](/sheets/dfir/dfir-gui-tools)