A forensic copy is intended to preserve evidence, including unallocated space and deleted-file remnants. Ordinary disk cloning can be useful for a working duplicate, but evidence handling requires stricter controls than a convenient bootable clone.
A defensible acquisition records who handled the device, when it was connected, what tool and settings were used, and whether the source changed. Investigators normally use a tested write blocker and calculate cryptographic hashes for the source and acquired image. The hash values, acquisition log, and chain of custody are kept with the case.
A disk-to-disk clone, a RAW image file, and a logical file backup are different outputs. A logical backup omits unallocated space. A bitstream image may preserve readable sectors, but it still needs independent validation before anyone calls it forensic evidence. Neither a clone nor a hash can recover sectors that hardware cannot read.
Power down the source and document its make, serial number, capacity, and condition. Do not let Windows mount an evidentiary disk read-write. For formal investigations, use a write blocker, validated imaging software, a destination with sufficient capacity, and an independent hash tool under the organization's procedures.
If the drive clicks, disappears, or reports repeated I/O errors, stop consumer imaging attempts. A professional lab may be able to stabilize it. For a personal working copy of a healthy drive, confirm that the destination is at least as large in bytes and contains no files you need to keep.
After acquisition, compare recorded hash values using a trusted method and keep the original disconnected. If a sector could not be read, record the error and its location; a successful completion message alone is not proof of a complete acquisition.
For published evidence-handling practices, consult the NIST guide to forensic techniques in incident response. The exact controls required for legal work depend on the jurisdiction and the organization.
Qiling Disk Master can copy readable sectors to another disk. Its ordinary clone workflow is not a certified forensic acquisition process and does not provide a chain-of-custody record or independent source hash. Use it as a working copy of a healthy personal drive, not as the sole basis for legal evidence.
Step 1. Connect the replacement disk with an enclosure that matches its SATA or NVMe interface. Open Qiling Disk Master and select Tools and utilities > Disk/Partition clone. Confirm that the source is healthy and the target is at least as large in bytes; avoid booting or writing to the source more than necessary.

Step 2. On the source screen, select the whole disk row by model and capacity, not just its C: partition. Record both disk identities before making a selection; the screenshot shows sample disks rather than your evidence drive. Click Next.

Step 3. Select Sector by sector clone on this source screen only if the complete source fits on the target and every readable sector is needed. This mode can take much longer and cannot repair unreadable areas. For formal evidence, use the separate write-blocked, validated acquisition process described above.

Step 4. Choose the replacement disk as the destination by model and capacity; click Next. An equal nominal capacity may still be a few sectors smaller, so compare the actual byte capacities. All existing destination data will be overwritten.

Step 5. Review the source and target disks and the resulting partition layout. Check that sector mode remains selected and the full source disk is represented. Do not mistake the sample disk in the screenshots for your own. Click Proceed, accept the overwrite warning, and wait for completion without disconnecting either drive.

Step 6. Do not modify the original. Verify the working copy independently and document any read errors before analyzing it. Keep the source unchanged until the result is verified.
For a damaged or failing source, do not keep retrying a consumer sector clone; repeated reads can reduce the chance of professional recovery.
A normal clone does not establish the write protection, validation, and handling record required for formal evidence. Follow your examiner or organization's procedure.
It can copy readable sectors that may contain remnants, but recovery depends on overwriting, TRIM, encryption, and the condition of the media.
Preserve the source, document every step, and verify the acquired data. Use Qiling sector cloning only for an appropriate working copy; formal forensic imaging requires additional controls.