A disk needs to leave the building as evidence, not just a copy, and ewfacquire is the tool for that. It turns a Linux device or raw image into an EWF forensic image with case metadata attached and a hash to prove nothing changed. This guide covers running that acquisition and checking the result with ewfinfo. The examples use ewfacquire 20140814 from Ubuntu package ewf-tools version 20140814-1build3. Allow at least 15 minutes for preparation, then as long as the source takes to read. A large disk can take hours.
You need the ewf-tools package, a destination filesystem with enough free space, and a source that must not be changed during acquisition. Imaging a block device normally requires elevated privileges. Writing the image into a directory you own does not.
Start by confirming the installed binary and list block devices without mounting or changing them:
$ command -v ewfacquire
/usr/bin/ewfacquire
$ ewfacquire -V
ewfacquire 20140814
$ lsblk -o NAME,SIZE,RO,TYPE,MOUNTPOINTS
Replace /dev/sdX below with the source device only after checking its size, read-only state and mountpoints. A wrong device path can acquire the wrong evidence, and later commands cannot undo that choice. Unmount the source through your normal incident process before imaging it. Do not use sudo umount or power-cycle a live system as a guess.
Choose a new destination such as /evidence/case-042/disk-01. The -t value is a target filename without its extension. Do not place it on the source device or in a directory that another process synchronises or cleans automatically.
The default mode asks questions and shows a final overview before it starts. This is useful when you are learning the tool or checking metadata interactively:
$ sudo ewfacquire -t /evidence/case-042/disk-01 /dev/sdX
Review every prompt. The installed command defaults to the encase6 format, 512 bytes per sector, 64 sectors per chunk, two read-error retries, offset zero, and acquisition of all available bytes. The default segment size is 1.4 GiB. The default media flag is physical in the option interface, although device detection and the attended prompts can display the corresponding media information.
Set the case number, description, evidence number, examiner and notes to values that match your evidence record. Use removable, optical or memory for the media type when fixed is not correct. Select physical unless you intentionally acquired a logical view. At the final confirmation, stop if the source, target or metadata is wrong.
Checkpoint: after confirmation, the tool prints an acquisition start message and progress. It also calculates an MD5 digest by default. Do not treat the digest as proof that the correct device was selected; it only identifies the bytes that were read.
For a documented workflow, supply the important values on the command line and use unattended mode only after reviewing them. This example acquires the whole source, calculates an additional SHA-256 digest, writes an error log, and keeps the target basename separate from the device name:
$ sudo ewfacquire -q -u \
-f encase6 \
-C CASE-042 -D 'Laptop disk acquisition' \
-E EVIDENCE-01 -e 'EXAMINER NAME' \
-N 'Source sealed before acquisition' \
-m fixed -M physical \
-d sha256 -l /evidence/case-042/disk-01.log \
-t /evidence/case-042/disk-01 \
/dev/sdX
Keep -u out of the command until the values are checked. It disables interaction, so it removes the last chance to correct a mistaken target or case number. -q reduces status output; omit it when you need progress on the terminal. If the device is larger than the intended acquisition, add -B NUMBER_OF_BYTES only when that limit is part of the evidence plan. Use -o OFFSET for a documented starting offset, not to skip inconvenient errors.
A failing disk will eventually throw a read error, and how you handle it becomes part of the evidence record. ewfacquire reads until a read error, retries each failed read twice by default, and uses the error granularity to decide how much data a failed region represents. Increase -r only when your procedure justifies more retries. More retries can prolong an unstable device and do not repair it.
The -w option tells the program to zero sectors on a read error to mimic EnCase behaviour. This changes the captured representation of unreadable data, so do not add it casually. Record the choice in the case notes and retain the acquisition log. Without -w, a failed acquisition may stop before producing a usable complete image.
If an interrupted run leaves resumable output, -R resumes acquisition at a safe point. Confirm that the target files belong to the intended case before using it. Do not resume into a renamed or partially replaced target. If the source has changed, start a new acquisition and explain why in the record.
List the files without altering them. An encase6 acquisition commonly produces a first segment ending in .E01, followed by additional numbered segments when required:
$ ls -lh /evidence/case-042/disk-01.E01
$ ewfinfo /evidence/case-042/disk-01.E01
EWF information
...
$ sed -n '1,80p' /evidence/case-042/disk-01.log
The exact ewfinfo formatting depends on the installed libewf build. Check that the media size, sector size, case metadata and segment set match your acquisition record. The log should contain the digest and any acquisition errors. If the image is incomplete or the metadata is wrong, quarantine it as an unsuccessful attempt rather than silently editing files.
Never overwrite the source to recover space. Keep the original device unchanged, protect the EWF segments and log with your case permissions, and make a separate working copy before analysis. If the command wrote an unwanted target, stop first, record its path, and remove it only under your evidence-retention procedure. Deleting an image is irreversible.
ewfacquire acquires data and metadata into EWF. It does not mount the image, prove that a filesystem is healthy, or replace an evidence-handling record. It can read a device directly on Linux and can also convert a raw file, including split raw input such as usb256.raw.0??. For optical raw material, -T DISC.cue supplies a CUE-format table of contents.
For a raw file, the command normally needs no elevated privilege if the file and destination are readable and writable by your user:
$ ewfacquire -t /evidence/case-042/usb \
-C CASE-042 -E EVIDENCE-02 -e 'EXAMINER NAME' \
/path/to/usb256.raw.0??
Check the shell glob before running an unattended conversion. If it matches nothing, the literal pattern may be passed as the source and fail. If it matches an unexpected set of files, stop and correct the path.