Description
Storage media can be copied for forensic acquisition with hashing, logging, and options beyond ordinary GNU dd. This is useful for investigators and administrators who need repeatable disk imaging workflows.
Forensic imaging can overwrite evidence or private data if device names are wrong. Confirm source and destination devices, write blockers, hashes, and chain-of-custody requirements before running it.