Криминалистическое создание образов дисков

★ 8.4 · security

acquiring-disk-image-with-dd-and-dcfldd is a Claude Code skill that creates forensically sound bit-for-bit disk images using dd or dcfldd on a Linux forensic workstation, with built-in MD5 and SHA-256 hash verification to preserve evidence integrity throughout acquisition. The workflow covers the full chain of custody: identifying the target block device, enabling software or hardware write-blocking, capturing the image, hashing the source before and after to confirm no changes occurred, and generating a structured acquisition report. dcfldd supports simultaneous dual hashing, split output for large drives, and a built-in verification pass, while dd handles compressed and partial acquisitions. Designed for digital forensics examiners and incident responders who need a legally defensible copy of a suspect drive, USB device, or memory card before any destructive analysis or law-enforcement proceedings.