Read EWF Evidence Metadata Safely with ewfinfo

You will finish with a repeatable, read-only workflow for inspecting the metadata in an Expert Witness Compression Format (EWF) image. You will identify the installed version, read the complete segment set through its first file, choose an unambiguous date format, and narrow the output when you need one particular group of fields.

Allow about fifteen minutes for a first pass. You need a shell, the ewf-tools package, and an EWF image that you are authorised to examine. The examples assume a segment set whose first file is named evidence.E01. Replace that placeholder with the real path, and keep the original evidence mounted read-only or otherwise protected by your normal evidence-handling process.

Checkpoint: This workflow reads metadata. It does not mount, export, repair, verify or alter an image. Do not use a filename from an untrusted report without checking the path you are about to open.

1. Confirm the local command and version

Start with ordinary, read-only checks. No elevated privileges are needed:

$ command -v ewfinfo
/usr/bin/ewfinfo
$ ewfinfo -V
ewfinfo 20140814

Copyright (C) 2006-2021, Joachim Metz.
This is free software; see the source for copying conditions.
There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
$ dpkg-query -W -f='${Package} ${Version}\n' ewf-tools
ewf-tools 20140814-1build3

The installed command reports libewf's 20140814 build, packaged here as ewf-tools 20140814-1build3. Keep that detail with your examination notes. Command output can vary between libewf releases, especially in the formatting of diagnostics and metadata fields.

If command -v prints nothing, stop and install the package through your normal system change process. Do not copy a binary from an unknown source into the path merely to make the example work.

2. Check the option set before opening an image

Ask the installed binary for its help. This is useful when a guide, script or colleague has supplied an option from a different libewf build:

$ ewfinfo -h
ewfinfo 20140814

Usage: ewfinfo [ -A codepage ] [ -d date_format ] [ -f format ]
               [ -ehimvVx ] ewf_files

The local manual documents -A for the header codepage, -d for date display, -f for output format, and the information selectors -e, -i and -m. It also documents -v for verbose diagnostics and -V for the version. The help line includes -x, but the installed manual does not describe it, so this guide does not rely on it. Treat a mismatch between help and documentation as a reason to check the exact package build before scripting around it.

3. Inspect the complete segment set through its first file

Use the first segment as the positional argument. The manual says that ewf_files may be the first or the entire set of EWF segment files. In the common split-image case, starting with evidence.E01 lets libewf discover the related segments:

$ ewfinfo -- evidence.E01

The -- makes the boundary between options and the filename clear. It is especially useful when a path begins with a hyphen. For a path elsewhere, use an explicit path:

$ ewfinfo -- /srv/case-2026/evidence.E01

Do not pass only a later segment such as evidence.E03 when you intend to describe the whole image. Do not rename segments casually either: EWF sets use related names and identifiers, and a renamed or incomplete set may fail to open or produce an incomplete examination.

On success, text output starts with the ewfinfo version and presents sections such as acquiry information, EWF information, media information and digest hash information. The exact fields depend on what was stored in the image. A missing field is not proof that the underlying device lacked that property.

Checkpoint: Save the terminal output as examination data only after confirming that the input path identifies the intended image. The command is read-only, but redirecting output can still overwrite an existing report:

$ ewfinfo -- evidence.E01 > evidence-ewfinfo.txt
$ test -s evidence-ewfinfo.txt && echo 'metadata report written'
metadata report written

Choose a new report filename or confirm an existing one before using >. If you wrote the report to the wrong place, remove only that generated report through your normal cleanup process, never the source segments.

4. Make dates unambiguous

The default date format is ctime. That is familiar at a terminal but can be awkward in notes shared across regions. Use dm for day/month, md for month/day, or iso8601 for a machine-friendly representation:

$ ewfinfo -d iso8601 -- evidence.E01 > evidence-ewfinfo-iso8601.txt
$ test -s evidence-ewfinfo-iso8601.txt && echo 'ISO 8601 report written'
ISO 8601 report written

The date option changes how dates are displayed; it does not rewrite timestamps in the EWF files. Prefer iso8601 when the report will be parsed, compared or passed between teams. Keep the selected format in your notes so a later reader can interpret an older report correctly.

5. Narrow the report when reviewing one section

Use a selector when a full report is distracting. These commands still read the image and write no changes to it:

$ ewfinfo -i -- evidence.E01
$ ewfinfo -m -- evidence.E01
$ ewfinfo -e -- evidence.E01

-i shows acquiry information, -m shows media information, and -e shows EWF read error information. The useful output is image-specific. For example, the media section may report sector size and media size, while acquiry fields may include case or examiner data if those values were recorded. Do not infer that a blank or absent selector result means the image is healthy or that a field was deliberately cleared.

For an interchange format, request DFXML and capture it separately:

$ ewfinfo -f dfxml -- evidence.E01 > evidence-ewfinfo.xml
$ test -s evidence-ewfinfo.xml && echo 'DFXML report written'
DFXML report written

The default format is text; dfxml is the other format named by the local manual. Validate the resulting document with the DFXML-aware tool in your forensic workflow before treating it as structured input. Do not parse the human-readable text by fixed column positions: fields and spacing can change between releases.

6. Handle failures without changing the evidence

A non-zero result means the inspection did not complete successfully. Capture diagnostics while keeping the input untouched:

$ ewfinfo -v -d iso8601 -- evidence.E01 \
    > evidence-ewfinfo-verbose.txt \
    2> evidence-ewfinfo-errors.txt
$ status=$?
$ printf 'ewfinfo exit status: %s\n' "$status"
ewfinfo exit status: 0

In this example, status 0 is the expected successful result, but do not replace the value with a guessed status in your notes. With -v, verbose and debug output is sent to standard error when that support was enabled at compilation. Preserve both files if the status is non-zero, then check the path, segment completeness, permissions and package version. Avoid repeatedly opening a damaged image in ways your local evidence procedure does not permit.

Verbose output is diagnostic information, not a repair operation. ewfinfo has no documented option in this local manual for fixing segments. If you need recovery, export or verification, stop and use the separately approved libewf tool and procedure for that task. Those operations have different safety and evidential consequences.

Done means