Acquiring evidence with Guymager

To begin the acquisition process, right-click on the evidence drive (/dev/sdb in this example) and select Acquire image. Note that the Clone device option is also available should you wish to clone the evidence drive to another. Again, as previously mentioned, when cloning a device, the capacity of the destination device must be equal to or exceed that of the source (original) evidence drive:

Before the actual acquisition process starts, the investigator is prompted to enter details about themselves and the evidence under the following three sections:

  • File format:
    • File extensions: .dd, .xxx, and .Exx
    • Split ...

Get Digital Forensics with Kali Linux now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.