Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
libewf — C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART formats. | Kitploit
Tools/GitHubGitHub/libyal/libewf
Disk ForensicsForensicsData RecoveryDigital Forensics
GitHublibyal/libewf

libewf

C library and command-line toolkit for forensic EWF image handling: acquire, export, verify, recover, and mount evidence files in EnCase and SMART formats.

View Repository
312881 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

libewf is a library to access the Expert Witness Compression Format (EWF).

Project information:

  • Status: experimental
  • Licence: LGPL-3.0-or-later

Read or write supported EWF formats:

  • SMART .s01 (EWF-S01)
  • EnCase
    • .E01 (EWF-E01)
    • .Ex01 (EWF2-Ex01)

Not supported:

  • .Ex01 (EWF2-Ex01) bzip2 compression (work in progress)
  • .Ex01 (EWF2-Ex01) encryption

Read-only supported EWF formats:

  • Logical Evidence File (LEF)
    • .L01 (EWF-L01)
    • .Lx01 (EWF2-Lx01)

Other features:

  • empty-block compression
  • read/write access using delta (or shadow) files
  • write resume

Work in progress:

  • Dokan library support (experimental)
  • Python bindings (including Python 3 support)
  • write EWF2-Ex01 support
  • Multi-threading support

Planned:

  • write EWF-L01 and EWF2-Lx01 (long-term)

The libewf package contains the following tools:

  • ewfacquire; which writes storage media data from devices and files to EWF files.
  • ewfacquirestream; which writes data from stdin to EWF files.
  • ewfdebug; experimental tool does nothing at the moment.
  • ewfexport; which exports storage media data in EWF files to (split) RAW format or a specific version of EWF files.
  • ewfinfo; which shows the metadata in EWF files.
  • ewfmount; which FUSE mounts EWF files.
  • ewfrecover; special variant of ewfexport to create a new set of EWF files from a corrupt set.
  • ewfverify; which verifies the storage media data in EWF files.

For previous project contributions see:

  • libewf on SourceForge: https://sourceforge.net/projects/libewf

For previous stable releases see:

  • Downloads: https://github.com/libyal/legacy/tree/master/libewf

For more information see:

  • Project documentation: https://github.com/libyal/libewf/wiki/Home
  • How to build from source: https://github.com/libyal/libewf/wiki/Building
Download Tool