fox-it / acquire

acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container.
GNU Affero General Public License v3.0
91 stars 26 forks source link

Add option to acquire to collect UEFI #156

Open DissectBot opened 8 months ago

DissectBot commented 8 months ago

The UEFI partition is FAT based, and dissect.fat should just work. Might need some investigation into the differences between Windows and Linux based systems.

Zawadidone commented 8 months ago

Reference: https://docs.velociraptor.app/exchange/artifacts/pages/uefi/