Practical Forensic Imaging: Securing Digital Evidence with Linux Tools
Bruce Nikkel · No Starch Press · 2016
Identifier: ISBN 978-1-59327-793-2
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
The acquisition half of the job done properly with Linux command-line tools: write protection, image formats, attaching subject media, image management and transfer, integrity by cryptographic and piecewise hashing, PKI signatures and RFC 3161 timestamping, drive security (ATA passwords, Opal self-encrypting drives, BitLocker, FileVault), and difficult cases such as RAID, VM images and damaged media.
Who it is for, and when
Read this before you image anything that matters. It is the clearest treatment of evidence integrity as an engineering problem rather than a form to sign, and the hashing and timestamping chapters are the ones to cite when the authenticity of an image is challenged. Chapter 2 is free from the publisher.
What it does not cover
The interface and drive coverage was current in 2016 and now predates NVMe-only laptops, soldered storage and hardware-bound encryption where physical imaging is simply not available. Nothing on cloud or mobile acquisition, and nothing on the legal process for obtaining the media in the first place.
Go to the source
Open at nostarch.com (opens in a new tab)https://nostarch.com/forensicimaging
Details
- Type
- Book
- Written for
- Working examinerWorking examiner
- Author
- Bruce Nikkel
- Publisher
- No Starch Press
- Year
- 2016
- Identifier
- ISBN 978-1-59327-793-2
- Topics
- imaging, evidence-handling, encryption, linux
- Checked at source
Related entries
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.
Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.
NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.
An open-source library and tool set for the Expert Witness Compression Format (E01/Ex01), including ewfacquire to create images, ewfverify to check their integrity hashes, ewfinfo to read the metadata, and ewfmount to expose an image as a raw device. The repository remains actively maintained.
SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.