FICHA · AUR

dc3dd

is a patch to the GNU dd program, this version has several features intended for forensic acquisition of data.

  • forensics-tool
  • CLI
  • Launchable
  • Runs in terminal
official+codex · reviewed · May 31, 2026 description in en

Description

Storage media can be copied for forensic acquisition with hashing, logging, and options beyond ordinary GNU dd. This is useful for investigators and administrators who need repeatable disk imaging workflows.

Forensic imaging can overwrite evidence or private data if device names are wrong. Confirm source and destination devices, write blockers, hashes, and chain-of-custody requirements before running it.

How to run

dc3dd

Commands: dc3dd

Permissions

Permissions not analysed for this source yet.