Evimetry is built for integrity, reliability, security and speed. Instead of acquisition to evidence containers such as EWF, Evimetry uses the AFF4 forensic container to manage evidence storage.
AFF4 evidence containers provide similar forensic soundness properties as conventional images, with a focus on abstractions such as virtualised storage, sparse regions, lightweight compression, and block hashing. These abstractions allow flexibility around how much and in which order suspect data is acquired and where it is stored. Importantly, they also enable higher utilization of available CPU, network, and IO resources. This means faster acquisitions, faster evidence processing, and the ability to access evidence while it is being acquired.
Evimetry supports forensics on almost any computing conventional Intel/AMD computer, including PC & Mac, and virtualization environments such as Amazon EC2 & VMWare.