Acquisition Packet Generator

v0.9.0 · Pre-release Ready First signed release cycle

ByteCase Acquire

Create consistent acquisition documentation and case-ready records for digital evidence collection.

Make the acquisition record part of the acquisition

ByteCase Acquire makes acquisition documentation an intentional part of the workflow instead of an after-the-fact reconstruction.

Current release status

ByteCase Acquire v0.9.0 is prepared for its first pre-release cycle.

Signed Windows publication is pending Azure Artifact Signing certificate verification.

Explore the interface

See how the module structures the work.

Select a workspace to view the interface and understand how it supports the surrounding forensic workflow.

Capabilities

Built around the work.

Multiple devices and tools

Document multiple devices, acquisition tools, versions, methods, destinations, and outputs.

Structured acquisition details

Capture interfaces, write protection, timestamps, hashes, storage totals, errors, and deviations.

Review and configurable defaults

Use saved settings, report branding, validation warnings, and review-before-export.

Multiple export formats

Generate TXT, JSON, DOCX, and XLSX documentation.

Who this is for

Designed for practical forensic environments.

Examiners documenting computer, storage, or mobile acquisitionsSmall laboratories standardizing acquisition recordsTechnical reviewers reconstructing how an image or extraction was createdAgencies using established forensic acquisition platforms

When to use it

Good fits for the module.

  • Record source and destination information
  • Document multiple tools, versions, methods, and devices
  • Capture write protection, timestamps, hashes, errors, and deviations
  • Generate a consistent acquisition packet and tracking record

What it does not replace

Keep the boundary clear.

  • Forensic acquisition engines
  • Hardware or software write blockers
  • Tool-generated acquisition logs
  • Examiner validation of the acquisition method

Example workflow

From case input to saved record.

  1. 01

    Describe the evidence

    Record submitted devices, identifiers, condition, and case association.

  2. 02

    Document the method

    Identify acquisition types, connection paths, write protection, tools, and versions.

  3. 03

    Record results

    Capture destinations, timestamps, outputs, hashes, errors, and deviations.

  4. 04

    Review and generate

    Validate and save the acquisition records.

Detailed boundaries

What this module does not claim.

  • ByteCase Acquire documents an acquisition; it does not perform the acquisition.
  • The examiner remains responsible for validating tools and following agency procedures.
  • The v0.9.0 build is not yet presented as a signed public Windows release.

Development direction

Where the module can go next.

  • Publish the first signed Windows pre-release
  • Collect examiner testing feedback
  • Refine templates and packet formatting
  • Prepare Verify and Hub interoperability

Product status

v0.9.0 · Pre-release Ready

v0.9.0 prepared for the first signed pre-release cycle.

Current focusSigned publication, structured external testing, and refinement from examiner feedback.View development history →

ByteCase by Forensics Byte

Documentation that remains useful when the case returns.

Use focused standalone modules for specific workflow problems, then connect them only where shared data adds clear value.