Digital forensics EU-developed
Acquire
Collects forensic artifacts from live systems or disk images into lightweight containers for triage and subsequent independent investigation.
By Fox-IT · Netherlands
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- Fox-IT
- Recorded country
- Netherlands
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- AGPL-3.0
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteDissect Team at Fox-IT publishes Acquire as a separate installable tool.
Reported capabilities
- Live or image acquisition
- Artifact profiles
- Lightweight container output
Scope and limits
Part of the Dissect ecosystem but independently installable and usable for artifact collection; Fox-IT has UK group ownership.
Inspect the research evidence 3 source observations
identity / origin / capabilities / deployment
README describes independent pip installation and acquisition of forensic artifacts from live hosts and disk images; requires privileged access for raw disks.
Read sourcelicense
Actual license text is GNU Affero General Public License version 3.
Read sourcecountry / maintenance
Verified Dutch developer organization identifies NCC Group parent and shows Acquire updated in August 2026.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow