Digital forensics EU-developed

Acquire

Collects forensic artifacts from live systems or disk images into lightweight containers for triage and subsequent independent investigation.

By Fox-IT · Netherlands

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
Fox-IT
Recorded country
Netherlands
Product model
Open source
Deployment
Desktop/CLI
Software license
AGPL-3.0
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Dissect Team at Fox-IT publishes Acquire as a separate installable tool.

Reported capabilities

  • Live or image acquisition
  • Artifact profiles
  • Lightweight container output

Scope and limits

Part of the Dissect ecosystem but independently installable and usable for artifact collection; Fox-IT has UK group ownership.

Inspect the research evidence 3 source observations
  1. identity / origin / capabilities / deployment

    README describes independent pip installation and acquisition of forensic artifacts from live hosts and disk images; requires privileged access for raw disks.

    Read source
  2. license

    Actual license text is GNU Affero General Public License version 3.

    Read source
  3. country / maintenance

    Verified Dutch developer organization identifies NCC Group parent and shows Acquire updated in August 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow