pkg.sopackage field notes

brew / rank 2479

Install libewf with Homebrew

Library for support of the Expert Witness Compression Format. Version 20140816 via Homebrew; verified from local package data.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install libewf

provider-native install command

overview

Package summary

Library for support of the Expert Witness Compression Format

Commands and aliases

  • ewfacquire
  • ewfacquirestream
  • ewfdebug
  • ewfexport
  • ewfinfo
  • ewfmount
  • ewfrecover
  • ewfverify

history

Project history and usage

libewf is the libyal library and tool suite for reading, writing, acquiring, verifying, exporting, and mounting Expert Witness Compression Format evidence files. Its package-manager identity is tied to digital forensics because EWF/E01 images are common interchange artifacts between acquisition tools, forensic suites, and open-source analysis workflows.

Project history

Joachim Metz began documenting the EWF file format in March 2006, with libewf's legacy ChangeLog recording release-preparation work in April 2006. The project grew alongside a public working specification for the format, covering SMART, EnCase E01, logical evidence files, and later EWF2 variants.

The libyal repositories split the actively experimental libewf tree from a stable legacy tree. Homebrew's curation points at the legacy repository, while the project documentation and README describe the broader libewf effort.

Adoption history

EWF became important because forensic images produced by EnCase, FTK Imager, SMART, and related tools needed open readers and converters. libewf gave Unix package ecosystems a reusable C library plus tools such as ewfacquire, ewfinfo, ewfexport, ewfmount, and ewfverify.

Distribution packages under names such as libewf, ewf-tools, and ewftools made E01 handling available outside proprietary forensic workstations.

How it is used

Package users commonly install libewf for command-line acquisition and conversion, for mounting or inspecting EWF images, or as a dependency of forensic applications that need E01/S01/L01 support.

Why package nerds care

libewf is package-nerd useful because it turns a proprietary-forensics file family into a normal Unix library and set of small tools. It also carries one of the clearest public format documents for EWF, making it useful to preservation, incident response, and forensic packaging work.

Timeline

  • 2006-03: Initial public EWF specification revisions for the libewf project.
  • 2006-04: Legacy ChangeLog records first-release preparation and tool renames such as ewfcat to ewfexport and ewfmd5sum to ewfverify.
  • 2014: Legacy ChangeLog records stabilization work and synchronization with the experimental libewf tree.
  • 2026: The EWF specification document records maintenance through 2006-2026.

Related projects

  • Related projects include the libyal family of forensic libraries, The Sleuth Kit integrations, EnCase, FTK Imager, and forensic package sets that ship ewf-tools.

security posture

Risk level: green

library-like package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • library-like package without higher-risk signals

Signals

  • metadata:library-like

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
ewfacquireexecutableindexed executableDiscovered from the local executable index.
ewfacquirestreamexecutableindexed executableDiscovered from the local executable index.
ewfdebugexecutableindexed executableDiscovered from the local executable index.
ewfexportexecutableindexed executableDiscovered from the local executable index.
ewfinfoexecutableindexed executableDiscovered from the local executable index.
ewfmountexecutableindexed executableDiscovered from the local executable index.
ewfrecoverexecutableindexed executableDiscovered from the local executable index.
ewfverifyexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version20140816
manager updated
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:libewf
Version20140816
Package managerHomebrew
Homepagehttps://github.com/libyal/libewf
Repositoryhttps://github.com/libyal/libewf
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation