Legal Cyber Academy
BookPaidCurrent

Practical Forensic Imaging: Securing Digital Evidence with Linux Tools

Bruce Nikkel · No Starch Press · 2016

Identifier: ISBN 978-1-59327-793-2

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The acquisition half of the job done properly with Linux command-line tools: write protection, image formats, attaching subject media, image management and transfer, integrity by cryptographic and piecewise hashing, PKI signatures and RFC 3161 timestamping, drive security (ATA passwords, Opal self-encrypting drives, BitLocker, FileVault), and difficult cases such as RAID, VM images and damaged media.

Who it is for, and when

Read this before you image anything that matters. It is the clearest treatment of evidence integrity as an engineering problem rather than a form to sign, and the hashing and timestamping chapters are the ones to cite when the authenticity of an image is challenged. Chapter 2 is free from the publisher.

What it does not cover

The interface and drive coverage was current in 2016 and now predates NVMe-only laptops, soldered storage and hardware-bound encryption where physical imaging is simply not available. Nothing on cloud or mobile acquisition, and nothing on the legal process for obtaining the media in the first place.

Go to the source

Open at nostarch.com (opens in a new tab)

https://nostarch.com/forensicimaging

Details

Type
Book
Written for
Working examinerWorking examiner
Author
Bruce Nikkel
Publisher
No Starch Press
Year
2016
Identifier
ISBN 978-1-59327-793-2
Topics
imaging, evidence-handling, encryption, linux
Checked at source
  • A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.

  • Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.

  • NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.

  • An open-source library and tool set for the Expert Witness Compression Format (E01/Ex01), including ewfacquire to create images, ewfverify to check their integrity hashes, ewfinfo to read the metadata, and ewfmount to expose an image as a raw device. The repository remains actively maintained.

  • SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.