{"categories":[{"label":"Utilities","url":"https://skillfed.io/packages/category/utilities/8"},{"label":"Security","url":"https://skillfed.io/packages/category/security/2"},{"label":"Information Analysis","url":"https://skillfed.io/packages/category/scientific-engineering-information-analysis/3"},{"label":"Log Analysis","url":"https://skillfed.io/packages/category/internet-log-analysis"}],"enrichment":{"capability":"Acquire gathers forensic artifacts from disk images or live systems into a lightweight container, using the dissect framework to extract data from raw disk when possible.","skillfed_tags":["forensics","incident-response","triage"],"use_cases":["Quickly triage a compromised system by collecting forensic artifacts into a portable container for offline analysis.","Automate forensic evidence gathering from disk images during incident response workflows.","Extract OS-specific artifacts from live systems using profile-based collection (full, default, minimal).","Gather raw disk data when direct access is available, with automatic fallback to OS-level file access.","Build forensic investigation pipelines that integrate artifact collection via the dissect framework."],"what_it_does":"Acquire is a forensic triage tool that rapidly collects artifacts from disk images or running systems into a portable container format. It leverages the dissect framework to parse raw disk structures when possible, making it useful for digital forensic investigations and incident response workflows. The tool operates through configurable profiles (full, default, minimal, none) and module-based artifact gathering, with OS-specific logic to collect relevant evidence. It requires administrative access to read raw disk data but offers fallback modes to use the operating system for file access when direct disk reading is unavailable.\n\nThe package is maintained as part of the broader Dissect project by Fox-IT/NCC Group, with active development and a production-stable classification. It depends on dissect.cstruct and dissect.target for its core functionality, and is distributed as a pure Python wheel with low installation friction.","worth_installing":"Yes, if you need forensic artifact collection from disk images or live systems. The tool is actively maintained, has low install friction, and fills a specific role in digital forensics and incident response. The AGPL-3.0-or-later license requires copyleft compliance, which is appropriate for open-source forensic work but should be reviewed if you plan proprietary modifications. Requires Python >=3.10 and administrative access."},"id":"acquire","links":{"html":"https://skillfed.io/packages/acquire","md":"https://skillfed.io/packages/acquire.md","pypi":"https://pypi.org/project/acquire/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-02-25","license_spdx":"AGPL-3.0-or-later","license_treatment":"agpl","name":"acquire","python_support":"supports_current","summary":"A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container"},"popularity":{"monthly_downloads":158404,"position":10724,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"3.22"}
