To begin the acquisition process, right-click on the evidence drive (/dev/sdb in this example) and select Acquire image. Note that the Clone device option is also available should you wish to clone the evidence drive to another. Again, as previously mentioned, when cloning a device, the capacity of the destination device must be equal to or exceed that of the source (original) evidence drive:
Before the actual acquisition process starts, the investigator is prompted to enter details about themselves and the evidence under the following three sections:
- File format:
- File extensions: .dd, .xxx, and .Exx
- Split ...