Evidence acquisition is concerned with the collection of evidence from digital devices for subsequent analysis and presentation.
It is extremely important that the digital evidence is collected in a forensically-sound manner using acquisition tools that
do not affect the integrity of the evidence. This paper describes a forensic acquisition tool that may be used to access files
on a live system without compromising the state of the files in question. This is done in the context of the Reco Platform,
an open source forensic framework that was used to develop the prototype evidence acquisition tool both quickly and efficiently.
The paper also discusses the implementation of the prototype and the results obtained.
Keywords Live systems - evidence acquisition - Reco Platform