Ex. 3 Image Acquisition With Guymager - Kali LinuX
Ex. 3 Image Acquisition With Guymager - Kali LinuX
Ex. 3 Image Acquisition With Guymager - Kali LinuX
Guymager is another standalone acquisition tool that can be used for creating forensic
images and performing disk cloning. Developed by Guy Voncken, Guymager is
completely open source, has many of the same features of dc3dd, and is also only available
for Linux-based hosts. While some investigators may prefer CLI tools, Guymager is a GUI
tool and is for beginners, so it may be preferable.
For this acquisition, I'll use the very same 2-GB flash drive used in the dc3dd examples,
at the end of which we can compare results.
As previously done in the dc3dd acquisition, we should first ensure that we are familiar
with the devices attached to our machine, using the fdisk -l or sudo fdisk -l
command.
Running Guymager
Guymager can be started by using the menu in Kali Linux. Click on Applications on the
side menu, then click on Forensics and scroll down to Guymager:
Image acquisition using Guymager
• Image directory: The location of the created image file and log (info file)
• Image filename: The name of the image file
• Info filename: The name of the log file containing acquisition details:
Important note
Guymager also adds the convenience of having a Duplicate image... button
to create duplicate copies without having to repeat the data entry process.
For new users, you may want to specify the directory where the image file will be saved.
In the destination section, click on the Image directory button and choose your location.
You should choose a drive or directory that is unique to the case as the location for both
the image and the log/info file: