disk-imaging.md (18793B)
1 --- 2 title: "Disk & Memory Acquisition" 3 description: "Forensically sound imaging on Linux and Windows: order of volatility, write blocking, dd/dc3dd/ewfacquire, FTK Imager, WinPmem/DumpIt/AVML/LiME memory capture, hashing, chain of custody and mounting images read-only for analysis." 4 category: dfir 5 subcategory: "Acquisition" 6 tags: [dfir, forensics, acquisition, imaging, memory-forensics, chain-of-custody, e01, dd, windows, linux] 7 tools: ["dd / dcfldd / dc3dd", "ewfacquire (libewf)", "FTK Imager", "Guymager", "WinPmem", "DumpIt", "AVML", "LiME", "ewfmount / xmount", "Arsenal Image Mounter"] 8 difficulty: intermediate 9 updated: "2026-09-26" 10 --- 11 12 # Disk & Memory Acquisition 13 14 Everything downstream — timelines, registry parsing, carving, memory analysis — is only as good as the image it runs on. Acquisition is the one phase you cannot redo: a live box changes every second and a powered-off box loses its RAM forever. This card is the **order of operations**, the exact **`dd` / `ewfacquire` / FTK Imager** invocations, the **memory capture** tools per OS, and how to **hash, document and mount** the result so the analysis sheets ([EZ Tools](/sheets/dfir/ez-tools-kape), [Linux forensics](/sheets/dfir/linux-forensics), [Volatility](/sheets/dfir/volatility)) have something trustworthy to chew on. 15 16 > [!warning] Two rules that never bend 17 > 1. **Never write to the evidence.** Hardware write blocker on the suspect drive, or software blocking (`blockdev --setro`, Windows `diskpart` read-only attribute, FTK Imager's own protection) when you must go software-only. 18 > 2. **Hash before, hash after, write it down.** An image without a matching acquisition hash is a file, not evidence. 19 20 ## Order of volatility (RFC 3227) 21 22 Collect what disappears fastest first. Every step below the line you are on is destroying evidence above it. 23 24 | Priority | Evidence | Lifetime | Tool | 25 |---|---|---|---| 26 | 1 | Registers, CPU cache | nanoseconds | (not practically collectable) | 27 | 2 | **RAM**, routing/ARP tables, process table, kernel state | until reboot | WinPmem, DumpIt, AVML, LiME | 28 | 3 | Network connections, logged-in users, open files | seconds–minutes | `netstat`, `ss`, `w`, `lsof`, `Get-NetTCPConnection` | 29 | 4 | Temp files, swap/pagefile, hiberfil | until overwritten | included in disk image; grab `pagefile.sys`/`hiberfil.sys` explicitly | 30 | 5 | **Disk** | until overwritten | `dd`, `ewfacquire`, FTK Imager | 31 | 6 | Remote logs, SIEM, backups | retention policy | export from source | 32 | 7 | Physical configuration, topology | long | photos, notes | 33 34 > [!tip] Pull the plug or shut down? 35 > **Pull the plug** (hard power-off) preserves the disk as-is, including `hiberfil.sys`/`pagefile.sys`, and defeats shutdown-triggered anti-forensics. **Graceful shutdown** flushes caches and may fire a wiper. Default to: capture RAM live → pull the plug → image the disk. Exceptions: encrypted volumes you can only read while unlocked (image them **live**, or capture the key from RAM first), and servers where downtime is not yours to decide. 36 37 ## Documentation & chain of custody 38 39 Start the log before the first command. Every image needs: 40 41 - Case ID, examiner, date/time (**with timezone** — record the suspect machine's clock skew against a reference clock too) 42 - Device: make, model, serial, capacity, interface, physical condition, photos of labels 43 - Acquisition method, tool + version, write-blocker used 44 - **Source hash, image hash, verification result** 45 - Every hand-off: who, when, why, signed 46 47 ```bash 48 # Capture the timestamp and clock skew at the very start 49 date -u; hwclock -r 2>/dev/null # on the suspect box (Linux) 50 # Windows: 51 # w32tm /stripchart /computer:pool.ntp.org /samples:3 /dataonly 52 ``` 53 54 ## Live response (before you power off) 55 56 Only do this when the RAM capture is done (or you cannot capture RAM). Run tools **from your own media**, redirect output to your own media, and know that every command you run leaves artefacts — log what you ran so the analyst (probably you) can exclude them later. 57 58 ```bash 59 # Linux — volatile state to an evidence mount 60 E=/mnt/evidence/$(hostname)-$(date -u +%Y%m%dT%H%MZ); mkdir -p "$E" 61 date -u > "$E/date.txt" 62 uptime > "$E/uptime.txt" 63 w; last -F > "$E/logins.txt" 64 ps auxwwf > "$E/ps.txt" 65 ss -tulpan > "$E/net.txt" 66 ip a; ip r; arp -an > "$E/ip.txt" 67 lsof -nP > "$E/lsof.txt" 68 mount; df -h > "$E/mounts.txt" 69 lsmod > "$E/lsmod.txt" 70 cat /proc/mounts /proc/partitions > "$E/proc.txt" 71 ``` 72 73 ```powershell 74 # Windows — same idea, PowerShell (run from your USB, output to it) 75 $E="E:\evidence\$env:COMPUTERNAME-$(Get-Date -f yyyyMMddTHHmm)"; mkdir $E | Out-Null 76 Get-Date -Format o > "$E\date.txt" 77 Get-Process -IncludeUserName | Sort StartTime > "$E\ps.txt" 78 Get-CimInstance Win32_Process | Select ProcessId,ParentProcessId,CommandLine | Export-Csv "$E\cmdlines.csv" 79 Get-NetTCPConnection -State Established,Listen | Export-Csv "$E\net.csv" 80 Get-NetNeighbor; Get-NetIPAddress; Get-DnsClientCache | Out-File "$E\netcfg.txt" 81 query user; net session; net use > "$E\sessions.txt" 82 Get-ScheduledTask | Export-Csv "$E\tasks.csv" 83 Get-Service | Export-Csv "$E\services.csv" 84 Get-SmbOpenFile; Get-SmbSession > "$E\smb.txt" 85 ``` 86 87 ## Memory capture 88 89 ### Windows 90 91 | Tool | Notes | Command | 92 |---|---|---| 93 | **WinPmem** (Velocidex) | Open source, signed driver, raw or AFF4 output. The default choice. | `winpmem_mini_x64_rc2.exe C:\evidence\mem.raw` | 94 | **DumpIt** (Magnet) | Single exe, one prompt, produces `.dmp` (Vol3 reads it). Good for junior responders. | `DumpIt.exe /OUTPUT E:\mem.dmp /QUIET` | 95 | **Magnet RAM Capture** | GUI, free, handles Secure Boot / VSM boxes that stop other drivers | click Start | 96 | **Belkasoft RAM Capturer** | GUI, free, low footprint | pick output dir, Capture | 97 | **FTK Imager** | File → Capture Memory; can also grab `pagefile.sys` in the same pass | GUI | 98 | **KAPE** | `--target MemoryFiles` collects hiberfil/pagefile/swapfile; use a `!SANS_Triage`-style target after RAM capture | see [EZ Tools](/sheets/dfir/ez-tools-kape) | 99 100 ```powershell 101 # WinPmem, raw image, then hash it 102 .\winpmem_mini_x64_rc2.exe E:\evidence\mem.raw 103 Get-FileHash E:\evidence\mem.raw -Algorithm SHA256 | Tee-Object E:\evidence\mem.raw.sha256 104 105 # Also copy the swap/hibernation files for Volatility / Hibr2Bin 106 # (locked while running — use FTK Imager's "Obtain Protected Files" or KAPE MemoryFiles) 107 ``` 108 109 > [!info] Size and time 110 > RAM image ≈ physical RAM (16 GB box → 16 GB file, 2–5 min over USB 3). Write to **external** media, never the suspect disk. If Volatility later fails to find symbols, capture `C:\Windows\System32\ntoskrnl.exe` too — Vol3 uses its PDB GUID to fetch the right symbol pack. 111 112 ### Linux 113 114 | Tool | Notes | Command | 115 |---|---|---| 116 | **AVML** (Microsoft) | Static binary, **no kernel module**, works on most kernels via `/proc/kcore` or `/dev/crash`. First choice. | `./avml mem.lime` | 117 | **LiME** | Kernel module, must be built against the target's exact kernel headers. Output format Vol3 reads natively. | `insmod lime-$(uname -r).ko "path=/mnt/evidence/mem.lime format=lime"` | 118 | **/proc/kcore** via `dd` | Last resort, huge, not a clean physical map | avoid | 119 120 ```bash 121 # AVML — compress on the fly to your evidence mount 122 ./avml --compress /mnt/evidence/mem.lime.compressed 123 # or plain 124 ./avml /mnt/evidence/mem.lime && sha256sum /mnt/evidence/mem.lime > /mnt/evidence/mem.lime.sha256 125 126 # LiME — build on a matching kernel, never on the suspect box if you can avoid it 127 git clone https://github.com/504ensicsLabs/LiME && cd LiME/src && make 128 sudo insmod ./lime-$(uname -r).ko "path=/mnt/evidence/mem.lime format=lime" 129 sudo rmmod lime 130 131 # For Volatility 3 you will need a symbol table for this kernel: 132 # dwarf2json linux --elf /usr/lib/debug/boot/vmlinux-$(uname -r) > $(uname -r).json 133 ``` 134 135 > [!tip] macOS 136 > Modern Apple silicon makes live RAM capture impractical without vendor tooling. Collect volatile state with `sysdiagnose`, `ps`, `lsof`, `nettop`, and unified logs (`log collect --output case.logarchive`), then image the disk from Recovery / target disk mode. 137 138 ## Disk imaging 139 140 ### Identify the device first (and do not mount it) 141 142 ```bash 143 lsblk -o NAME,SIZE,MODEL,SERIAL,TYPE,MOUNTPOINT,FSTYPE 144 sudo fdisk -l /dev/sdb 145 sudo smartctl -i /dev/sdb # serial, firmware, power-on hours — into the log 146 sudo hdparm -I /dev/sdb | head -20 147 sudo blockdev --setro /dev/sdb # software write-block if no hardware blocker 148 sudo blockdev --getro /dev/sdb # → 1 149 # Stop the desktop from auto-mounting removable media before you plug in: 150 # gsettings set org.gnome.desktop.media-handling automount false 151 ``` 152 153 ```powershell 154 # Windows — find the disk and make it read-only in diskpart (no hardware blocker) 155 Get-Disk | ft Number,FriendlyName,SerialNumber,Size,PartitionStyle 156 diskpart 157 # DISKPART> select disk 2 158 # DISKPART> attributes disk set readonly 159 # DISKPART> attributes disk (verify "Read-only: Yes") 160 ``` 161 162 ### `dd` family (raw images) 163 164 ```bash 165 # Baseline hash of the source (slow, but the gold standard) 166 sudo sha256sum /dev/sdb | tee /mnt/evidence/sdb.source.sha256 167 168 # Plain dd — works everywhere, no progress, no error handling 169 sudo dd if=/dev/sdb of=/mnt/evidence/sdb.dd bs=4M conv=noerror,sync status=progress 170 171 # dcfldd — hashes while imaging, splits, verifies 172 sudo dcfldd if=/dev/sdb of=/mnt/evidence/sdb.dd bs=4M \ 173 hash=sha256 hashlog=/mnt/evidence/sdb.dd.hash \ 174 conv=noerror,sync statusinterval=256 175 176 # dc3dd — the DoD successor to dcfldd, best error handling, logs everything 177 sudo dc3dd if=/dev/sdb of=/mnt/evidence/sdb.dd \ 178 hash=sha256 hash=md5 log=/mnt/evidence/sdb.dd.log \ 179 rec=on # keep going on bad sectors, zero-fill them 180 181 # Split raw image into 2 GB chunks (FAT32 evidence drive, or just manageability) 182 sudo dc3dd if=/dev/sdb ofs=/mnt/evidence/sdb.dd.000 ofsz=2G hash=sha256 log=sdb.log 183 184 # Verify: image hash must equal source hash 185 sha256sum /mnt/evidence/sdb.dd 186 ``` 187 188 > [!warning] `conv=noerror,sync` matters 189 > Without `noerror` a single bad sector aborts the image. Without `sync` the bad block is skipped instead of zero-padded, and **every offset after it shifts**, breaking filesystem parsing. Use both, and record the bad-sector list from the log. 190 191 ### E01 / EWF (compressed, hashed, metadata-carrying) 192 193 The Expert Witness Format is what commercial suites (EnCase, FTK, X-Ways) expect, compresses well, embeds the case notes and checksums every chunk. Prefer it over raw when the image will be shared. 194 195 ```bash 196 sudo apt install libewf-tools ewf-tools # ewfacquire, ewfverify, ewfmount, ewfinfo 197 198 # Interactive (asks for case number, examiner, notes, compression, segment size) 199 sudo ewfacquire /dev/sdb 200 201 # Unattended 202 sudo ewfacquire -u -t /mnt/evidence/sdb -C CASE-042 -E 001 -e "DAEMON" \ 203 -D "Laptop SSD, Samsung 970, S/N ..." -N "Seized 2026-09-26 room 3" \ 204 -c best -S 4G -d sha256 -f encase6 /dev/sdb 205 206 ewfinfo /mnt/evidence/sdb.E01 # metadata + stored hashes 207 ewfverify /mnt/evidence/sdb.E01 # recompute and compare 208 ewfexport -t /mnt/evidence/sdb.raw /mnt/evidence/sdb.E01 # back to raw when a tool needs it 209 ``` 210 211 ### Guymager (Linux GUI) 212 213 Pre-installed on SIFT/Kali/Tsurugi. Right-click the device → **Acquire image** → pick `.dd` or `.E01`, fill case fields, tick **Calculate SHA-256** and **Verify image after acquisition**. It logs to a `.info` file next to the image. Fast, multithreaded, and the sanest option when a colleague has never used `dd`. 214 215 ### FTK Imager (Windows GUI + CLI) 216 217 The most common Windows imager. Free, runs from a USB ("FTK Imager Lite"), no install. 218 219 **GUI:** File → **Create Disk Image** → Physical Drive → select the suspect disk → Add destination → choose **E01** (or Raw/dd) → fill Evidence Item Information → set fragment size (0 = single file) and compression (6 default) → tick **Verify images after they are created** → Start. The summary window at the end has the MD5/SHA1 — screenshot it and save the `.txt` log it writes next to the image. 220 221 Other jobs FTK Imager does that nothing else free does as easily: 222 223 | Task | Menu | 224 |---|---| 225 | Copy locked live files (`$MFT`, hives, `pagefile.sys`, `NTUSER.DAT`) from a running box | File → **Obtain Protected Files** → tick *Password recovery and all registry files* | 226 | Export a folder tree from an image with timestamps intact | File → Add Evidence Item → browse → right-click → **Export Files** | 227 | Mount an E01 as a drive letter | File → **Image Mounting** → Physical & Logical, Read-only → Mount | 228 | Capture RAM | File → **Capture Memory** (tick *Include pagefile*) | 229 | Custom content image (only the paths you list, still hashed E01) | File → Create Disk Image → **Contents of a Folder**, or add to Custom Content Sources | 230 | View file slack, unallocated, and ADS | Evidence tree → `[unallocated space]`, hex pane bottom right | 231 232 ```bat 233 :: FTK Imager CLI (ftkimager.exe, separate download) — image with verification 234 ftkimager.exe \\.\PhysicalDrive2 E:\evidence\pd2 --e01 --frag 4G --compress 6 ^ 235 --case-number CASE-042 --evidence-number 001 --examiner DAEMON ^ 236 --description "Dell laptop SSD" --verify 237 238 :: List physical drives 239 ftkimager.exe --list-drives 240 ``` 241 242 ### Live imaging (encrypted / cannot power off) 243 244 When BitLocker/LUKS/FileVault means a dead image is ciphertext, image the **logical, unlocked volume** while it is mounted, and accept that the image is not a perfect snapshot. 245 246 ```bash 247 # Linux LUKS — image the mapped device, not the raw partition 248 sudo dc3dd if=/dev/mapper/luks-xxxx of=/mnt/evidence/root-decrypted.dd hash=sha256 log=root.log 249 ``` 250 251 ```bat 252 :: Windows BitLocker — logical drive letter, plus grab the recovery key while you can 253 manage-bde -protectors -get C: > E:\evidence\bitlocker-keys.txt 254 ftkimager.exe C: E:\evidence\C-logical --e01 --verify 255 ``` 256 257 > [!tip] Cloud and virtual machines 258 > VMs: snapshot, then copy the `.vmdk`/`.vhdx`/`.qcow2` and the `.vmem`/`.vmsn` (that *is* the memory image). `qemu-img convert -f vmdk -O raw disk.vmdk disk.raw` gets you something every tool reads. Cloud: snapshot the volume (AWS `create-snapshot`, Azure `az snapshot create`), attach to a forensic instance in the same region, image from there — do not download 500 GB over the internet. 259 260 ## Hashing & verification 261 262 ```bash 263 # Multiple algorithms in one pass (GNU coreutils 9+ or via hashdeep) 264 hashdeep -c md5,sha256 -e /mnt/evidence/sdb.dd > sdb.dd.hashes 265 # Verify later against that file 266 hashdeep -c md5,sha256 -a -k sdb.dd.hashes /mnt/evidence/sdb.dd 267 268 # Hash a split image as one stream 269 cat sdb.dd.0* | sha256sum 270 271 # Hash every file inside a mounted image (for a known-good/bad comparison later) 272 find /mnt/img -type f -exec sha256sum {} + > case-filehashes.txt 273 ``` 274 275 ```powershell 276 Get-FileHash E:\evidence\pd2.E01 -Algorithm SHA256 277 certutil -hashfile E:\evidence\pd2.E01 SHA256 # no PowerShell needed 278 ``` 279 280 > [!info] MD5 is fine here 281 > MD5 collisions are a real cryptographic weakness but irrelevant to proving an image was not altered by accident. Courts and tools still use MD5+SHA1; adding SHA-256 costs nothing. Record all of them. 282 283 ## Mounting images for analysis (read-only, always) 284 285 ```bash 286 # Raw image: find partition offsets, then mount one 287 sudo mmls sdb.dd # Sleuth Kit: sector offsets of each partition 288 sudo fdisk -l sdb.dd 289 sudo mount -o ro,loop,noexec,noload,offset=$((2048*512)) sdb.dd /mnt/img # ext4 (noload = don't replay journal) 290 sudo mount -o ro,loop,noexec,show_sys_files,streams_interface=windows,offset=$((1050624*512)) sdb.dd /mnt/img # NTFS via ntfs-3g, exposes $MFT and ADS 291 # Whole disk as block devices 292 sudo losetup -rfP --show sdb.dd # → /dev/loop0, /dev/loop0p1, ... (-r read-only, -P scan partitions) 293 sudo mount -o ro,noexec /dev/loop0p2 /mnt/img 294 sudo losetup -d /dev/loop0 295 296 # E01: expose as raw first 297 sudo mkdir -p /mnt/ewf && sudo ewfmount sdb.E01 /mnt/ewf # → /mnt/ewf/ewf1 (raw view) 298 sudo losetup -rfP --show /mnt/ewf/ewf1 299 # or xmount, which also fakes a writable overlay (cache file) so tools that insist on writing work 300 sudo xmount --in ewf sdb.E01 --out raw --cache /tmp/sdb.cache /mnt/xm 301 302 # LVM inside an image 303 sudo losetup -rfP --show sdb.dd && sudo vgscan && sudo vgchange -ay && lsblk 304 # Windows VSS shadow copies inside an NTFS image 305 sudo vshadowinfo /dev/loop0p2 && sudo vshadowmount /dev/loop0p2 /mnt/vss && ls /mnt/vss # vss1, vss2 ... 306 ``` 307 308 ```powershell 309 # Windows: Arsenal Image Mounter (free, handles E01/raw/VHD, true disk-level mount so 310 # VSS and BitLocker-unlocked volumes behave). Mount → pick image → "Read only" → OK. 311 # FTK Imager: File → Image Mounting → Mount Type "Physical & Logical", Mount Method "Block Device / Read Only". 312 # Native for VHD/VHDX only: 313 Mount-DiskImage -ImagePath E:\evidence\disk.vhdx -Access ReadOnly 314 ``` 315 316 > [!warning] `ro` is not a write blocker 317 > A read-only mount stops *you* writing; it does not stop a journaling filesystem replaying its journal on mount (hence `noload` on ext4), and it does not stop macOS Spotlight or Windows indexing from touching an image file you open in a GUI. Analyse **copies** of the image, keep the original hashed on a shelf. 318 319 ## Quick decision table 320 321 | Situation | Do | 322 |---|---| 323 | Running Windows workstation, suspected malware | RAM (WinPmem) → protected files (FTK Imager) → pull plug → E01 of disk | 324 | Running Linux server, cannot reboot | AVML → live response script → `dc3dd` of `/dev/mapper/*` if encrypted, else schedule downtime for a dead image | 325 | Powered-off laptop, unknown encryption | Do **not** boot it. Pull drive, hardware blocker, E01. Check `ewfinfo`/`mmls` for BitLocker signatures; hunt for recovery key in the user's cloud account or AD `msFVE-RecoveryInformation` | 326 | USB stick / SD card | Blocker, `dc3dd`, then [carve](/sheets/dfir/strings-file-triage) — small media are mostly deleted files | 327 | Phone | Different discipline entirely (Cellebrite/GrayKey/ALEAPP/iLEAPP); at minimum: airplane mode, Faraday bag, note lock state | 328 | VM | Snapshot, copy `.vmdk` + `.vmem`, convert with `qemu-img` | 329 330 ## Next steps 331 332 - Windows image → [EZ Tools & KAPE](/sheets/dfir/ez-tools-kape) for parsing, [Digital Forensics reference](/sheets/dfir/forensics) for what to look for, [Registry (RECmd)](/sheets/dfir/recmd) 333 - Linux image → [Linux forensics](/sheets/dfir/linux-forensics) 334 - Memory image → [Volatility 3](/sheets/dfir/volatility) 335 - Unknown files, unallocated space → [strings & file triage](/sheets/dfir/strings-file-triage) 336 - Point-and-click review → [GUI tools](/sheets/dfir/dfir-gui-tools)