Home / Alt manpages / ewfexport(1)

  • ewfexport(1)
  • User command
  • linux

Export EWF Evidence Safely with ewfexport

You will export data from an Expert Witness Format (EWF) image to a raw file, while leaving the source segments untouched and recording a digest of the exported bytes. This guide uses ewfexport 20140814 from the Debian package ewf-tools version 20140814-1build3. Allow 10 to 20 minutes for the command setup, then longer for the export itself if the image is large.

You need a readable EWF segment set, enough free space for the destination, and a shell. The first segment, such as evidence.E01, is enough for the command to discover the set when the other segments are beside it and follow the normal naming scheme. Use an ordinary account for a read-only source in an accessible directory. Use sudo only if the filesystem permissions genuinely require it, not as a default part of forensic work.

1. Check the installed tool

Confirm which binary will run and record its version before relying on an example:

$ command -v ewfexport
/usr/bin/ewfexport
$ ewfexport -V
ewfexport 20140814

The installed help is more current than the 2014 manpage in a few details. It lists sha256 as an additional digest, and says the sector-chunk option is not used for raw and files output. The manpage remains the local reference for the command's workflow and safety boundaries. Do not copy options from a different libewf build without checking its own help.

Checkpoint

Save the version and the absolute path of the binary in your case notes. If command -v finds nothing, stop and install or enable the package through your normal system process before handling the evidence.

2. Inspect the source without exporting it

Check that the first segment is readable and that its directory contains the expected set. This does not alter the image:

$ ls -lh /case/source/evidence.E01
$ find /case/source -maxdepth 1 -type f -name 'evidence.E*' -printf '%f\n' | sort

Replace /case/source/evidence.E01 with the real path. Keep the source path separate from the destination path. A typo in the first segment or a missing later segment normally causes an open or read error; it is not a reason to guess at a replacement file.

3. Export a raw image to a new destination

Use -f raw explicitly when the result must be a raw byte-for-byte view of the exported range. The default format is raw, but spelling it out makes a case command easier to audit:

$ ewfexport -f raw -t /case/output/evidence.raw \
    /case/source/evidence.E01

Without -u, ewfexport can ask for export details interactively. That is useful for a one-off run, but the command above supplies the format and target directly. Add -u when a script or unattended job must not wait for input:

$ ewfexport -f raw -u -t /case/output/evidence.raw \
    /case/source/evidence.E01

Do not use shell redirection for this workflow unless you deliberately want raw data on standard output. The -t - form is supported only for raw output. A target beginning with an existing filename deserves particular care: establish a new output directory or choose a new name first. The exporter can replace data at the destination, while it does not modify the EWF source.

During an interactive run, the program reports its start offset, byte count, progress and an MD5 digest. If you give no range, it exports all available bytes. For a deliberate range, use an offset and byte count:

$ ewfexport -f raw -o 1048576 -B 4194304 \
    -t /case/output/evidence-part.raw /case/source/evidence.E01

The example starts at byte 1,048,576 and exports 4,194,304 bytes. Keep the values within the image's reported size. An offset is a byte position, not a sector number.

4. Add and record an independent digest

ewfexport calculates MD5 over the exported data and can calculate an additional digest with -d. The installed build accepts sha1 and sha256; the local manpage documents sha1 and warns that it is not used for raw and files formats. The exporter digest is useful for documenting exactly what it wrote, but it does not replace your evidence-handling policy.

$ ewfexport -f raw -d sha256 -t /case/output/evidence.raw \
    /case/source/evidence.E01

Capture the terminal output in the case record, or send export errors and digests to a log file with -l:

$ ewfexport -f raw -d sha256 \
    -l /case/output/ewfexport.log \
    -t /case/output/evidence.raw /case/source/evidence.E01

Keep the log with the case metadata and verify that the destination and log are both on the intended filesystem.

5. Verify the result and handle errors

After a successful export, check the destination size and calculate a second digest with a separate tool:

$ ls -lh /case/output/evidence.raw
$ sha256sum /case/output/evidence.raw
<sha256 digest>  /case/output/evidence.raw

The separately calculated value should agree with ewfexport's SHA-256 value when the same complete export was made. If you exported only a range, compare the digest for that range, not for the original image. Keep the EWF segments until the output has been checked and accepted.

Do not use -w casually. It tells ewfexport to write zero sectors to the output when a checksum error is encountered, imitating EnCase-style behaviour. That can produce an output file which continues past damaged input while concealing the original bytes in the exported copy. For forensic preservation, leave it off unless your procedure explicitly requires that policy and records the affected sectors.

If the command fails, preserve the source and inspect the error, permissions, free space and segment set. Remove only an incomplete destination that you have positively identified as disposable, then rerun to a fresh name. Do not overwrite the source, and do not treat a completed file as trustworthy until its size and digest have been recorded.

6. Export another EWF format only when required

The -f option also supports EWF-derived formats including ewf, ewfx, encase7 and smart. Choose one only when the receiving tool requires it. Compression settings use -c, with a method and level such as deflate:best; bzip2 is supported only by EWF2 formats. The segment size option -S defaults to 1.4 GiB, has a 1.0 MiB minimum, and is not used for the files format.

For an ordinary raw export, leave -c and -S alone. Extra format options make the command harder to review and can change the output's compatibility. Check the installed ewfexport -h immediately before selecting a non-raw format.

Done means

  • The installed version and source segment set are recorded.
  • The EWF source remains unchanged and the destination is in a separate location.
  • The format, target, offset and byte count are explicit where the case requires them.
  • ewfexport's digest and a separate verification digest agree for the exported range.
  • Any checksum-error policy, especially -w, is deliberate and documented.