"This tool allows to triage a disk of a remote computer (client) that is restarted with a purposely built forensic operating system. It is a remote forensic disk imaging solution, although the term imaging is misleading in this case. While performing this investigation a server side sparse evidence file is written. This work process is against most forensic best practices that are documented as most describe investigation starts by making a forensic copy of the full disk.
The Raqet project deliberately breaks with this practice. It is the authors opinion that current disk sizes do no longer make it practical nor proportional to always make a full bit-copy. E.g. to save the forensic relevant data of a hacked web server one could argue that the web server log files are sufficient. Especially as most of the web server content is actually from the victim and not from the attacker."?raqet.github.io/?