$npx skillfedfor your agent

acquire

A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container

With conditionsPyPI UtilitiesReleased Feb 2026158.4K downloads / moAGPL-3.0-or-laterPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — acquire-3.22-py3-none-any.whl
v3.22 · released 2026-02-25 · Python >=3.10 · 2 runtime deps: dissect.cstruct, dissect.target

Yes, if you need forensic artifact collection from disk images or live systems. The tool is actively maintained, has low install friction, and fills a specific role in digital forensics and incident response. The AGPL-3.0-or-later license requires copyleft compliance, which is appropriate for open-source forensic work but should be reviewed if you plan proprietary modifications. Requires Python >=3.10 and administrative access.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python >=3.10 and administrative (root/sudo) access to read raw disk data; fallback modes available via --fallback or --force-fallback flags.
  • Low install friction with a pure Python wheel.
  • Active maintenance as of 2026-08-12 with a recent release on 2026-02-25.

License · maintenance · safety

AGPL-3.0-or-later (agpl) — Licensed under AGPL-3.0-or-later, which requires that any modifications or derivative works be distributed under the same license and made available to users. This is a strong copyleft obligation suitable for open-source projects but may constrain commercial or proprietary use.

last release 2026-02-25 (170 days) · last repo commit 2026-08-12 · 123 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 158,404 downloads/mo, #10,724 on PyPI

Verify before relying

pip install acquire

from acquire import ...

sudo acquire
  • Exact API surface and programmatic usage patterns beyond the CLI tool
  • Performance characteristics on large disk images or systems
  • Supported operating systems and artifact types beyond OS detection
Same gist for agents: .md · .json

What it is and what it does

Acquire is a forensic triage tool that rapidly collects artifacts from disk images or running systems into a portable container format. It leverages the dissect framework to parse raw disk structures when possible, making it useful for digital forensic investigations and incident response workflows. The tool operates through configurable profiles (full, default, minimal, none) and module-based artifact gathering, with OS-specific logic to collect relevant evidence. It requires administrative access to read raw disk data but offers fallback modes to use the operating system for file access when direct disk reading is unavailable.

The package is maintained as part of the broader Dissect project by Fox-IT/NCC Group, with active development and a production-stable classification. It depends on dissect.cstruct and dissect.target for its core functionality, and is distributed as a pure Python wheel with low installation friction.

Use it for

  • Quickly triage a compromised system by collecting forensic artifacts into a portable container for offline analysis.
  • Automate forensic evidence gathering from disk images during incident response workflows.
  • Extract OS-specific artifacts from live systems using profile-based collection (full, default, minimal).
  • Gather raw disk data when direct access is available, with automatic fallback to OS-level file access.
  • Build forensic investigation pipelines that integrate artifact collection via the dissect framework.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need forensic artifact collection from disk images or live systems.

The tool is actively maintained, has low install friction, and fills a specific role in digital forensics and incident response. The AGPL-3.0-or-later license requires copyleft compliance, which is appropriate for open-source forensic work but should be reviewed if you plan proprietary modifications. Requires Python >=3.10 and administrative access.

Install

acquire on PyPI

Before you install

Low install friction with a pure Python wheel. Active maintenance as of 2026-08-12 with a recent release on 2026-02-25. Requires Python >=3.10 and administrative access to read raw disk data, though fallback options exist.

Requires Python >=3.10 and administrative (root/sudo) access to read raw disk data; fallback modes available via --fallback or --force-fallback flags.

License in practice

Licensed under AGPL-3.0-or-later, which requires that any modifications or derivative works be distributed under the same license and made available to users. This is a strong copyleft obligation suitable for open-source projects but may constrain commercial or proprietary use.

Quickstart

pip install acquire

from acquire import ...

sudo acquire

Verify before relying

  • Exact API surface and programmatic usage patterns beyond the CLI tool
  • Performance characteristics on large disk images or systems
  • Supported operating systems and artifact types beyond OS detection

Package facts

LicenseAGPL-3.0-or-later agpl
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
dissect.cstructdissect.target
MaintenanceActively maintained 170 days since the last release
Last repo commit
First released
Downloads158,404 / month, #10,724 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: Internet :: Log AnalysisTopic :: Scientific/Engineering :: Information AnalysisTopic :: SecurityTopic :: Utilities

Evidence: acquire-3.22-py3-none-any.whl

Tags

Capabilities
forensic artifact collectiondisk image triagelive system forensicsdigital forensic acquisitionraw disk data extractionforensic containerincident response triage
Topics
forensicsincident-responsetriage

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “forensic artifact collection”

  • acquireAcquire gathers forensic artifacts from disk images or live systems…
  • dissect.targetdissect.target provides a unified API and command-line tools to parse…
  • volatility3Volatility 3 is a memory forensics framework that extracts and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also dissect.hypervisor · volatility3 · dissect.ntfs · dissect.volume · dissect.target · dissect.util · Acquisition · dissect.cstruct · openmed · dbt-colibri